Role & responsibilities
Location: [Bangalore / Hybrid / Remote 90%]
About Daimler Truck
As the world's leading commercial vehicle manufacturer, Daimler Truck develops, produces and sells trucks and buses under the brands Mercedes-Benz, Freightliner, Western Star, Thomas Built Buses, Setra, BharatBenz and FUSO. We are committed to transforming the transportation industry through innovation, sustainability, and cutting‑edge technology.
Position Overview
Daimler Truck is seeking a highly skilled and experienced Penetration Tester to join our global cybersecurity team. This role is critical in safeguarding our automotive technologies, connected vehicle systems, and enterprise infrastructure through comprehensive security assessments.
Key Responsibilities :
Penetration Testing & Security Assessment
- Conduct comprehensive penetration testing across web applications, mobile applications, thick client applications, and enterprise infrastructure
- Execute red team engagements to simulate advanced persistent threat scenarios
- Perform security assessments of automotive systems, including connected vehicle technologies and IoT implementations
- Evaluate cloud infrastructure, network segmentation, and hybrid environments
Research & Innovation :
- Stay current with emerging attack vectors, exploitation techniques, and security research
- Develop custom tools and methodologies to enhance testing capabilities
- Research automotive-specific security vulnerabilities and attack surfaces
- Contribute to the security research community through white papers and presentations
Reporting & Collaboration
- Prepare detailed technical reports with actionable remediation recommendations
- Present findings to technical teams and senior management
- Collaborate with development teams to implement security improvements
- Mentor junior security professionals and share knowledge across the organization
Experience :
- 4-6 years of hands-on penetration testing experience
- Proven track record in red team operations and advanced attack simulations
- Extensive experience with web application security testing (OWASP Top 10, etc.)
- Strong background in mobile application security (Android/iOS)
- Experience with thick client application assessments and reverse engineering
- Infrastructure penetration testing including network, Active Directory, and cloud environments
Certifications :
- OSCP (Offensive Security Certified Professional) - Mandatory
- Additional preferred certifications: CRTP, OSEP, OSWE, GPEN, GWAPT
Technical Skills :
- Proficiency with penetration testing frameworks (Metasploit, Cobalt Strike, etc.)
- Experience with web application testing tools (Burp Suite, OWASP ZAP, etc.)
- Mobile application testing tools (MobSF, Frida, objection, etc.)
- Static and dynamic analysis tools for thick client applications
- Network scanning and enumeration tools (Nmap, Nessus, etc.)
- Scripting languages: Python, PowerShell, Bash
- Knowledge of automotive protocols (CAN, LIN, FlexRay) is a plus
Research & Development :
- Demonstrated ability to research and develop new attack techniques
- Experience with vulnerability research and exploit development
- Understanding of threat intelligence and attack attribution
- Experience with security automation and CI/CD integration
Preferred Qualifications :
- Master's degree in Cybersecurity, Computer Science, or related field
- Experience in automotive or manufacturing industry
- Knowledge of industrial control systems (ICS/SCADA) security
- Cloud security experience (AWS, Azure, GCP)
- Container and Kubernetes security knowledge
- Published security research or CVE discoveries
- Speaking experience at security conferences (Black Hat, DEF CON, etc.)