Penetration Tester / Ethical Hacker (Offensive Security)

Zoho

India

Remote

INR 1,200,000 - 2,000,000

Part time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Zoho seeks an experienced Penetration Tester to perform multi-vector offensive security assessments against global networks, web applications and cloud environments. You will emulate advanced threat techniques, uncover exploitable weaknesses, and deliver detailed proof-of-concept reports to support hardening efforts.

The role is contract, remote and offshore, requiring 4–8 years of experience with at least 3 years in active testing. OSCP or GPEN is mandatory; OSCE/OSWE preferred.

Qualifications

  • 3+ years of dedicated offensive security testing and red-teaming experience.
  • Mandatory OSCP or GPEN certification.
  • Experience across networks, web apps, and cloud environments.

Responsibilities

  • Execute comprehensive network and web application penetration tests, using automated scanning and manual techniques.
  • Conduct realistic red-teaming campaigns, including social engineering and perimeter assessment.
  • Develop custom exploitation scripts in Python, PowerShell and Bash to demonstrate risk.
  • Assess cloud infrastructure entry points, including API auth weaknesses and misconfigurations.
  • Document and present vulnerability disclosure reports with CVSS scoring and remediation steps.
  • Perform post-remediation verification sweeps and re-testing of patched systems.
  • Collaborate with blue-team to tune SIEM rules and alerts.

Skills

Offensive security testing
Red teaming
Python
PowerShell
Bash
Cloud security assessments

Education

OSCP or GPEN certification
OSCE / OSWE preferred

Job description

Penetration Tester / Ethical Hacker (Offensive Security)

Penetration Tester / Ethical Hacker (Offensive Security)

  • Employment Type: Contract
  • Work Mode: Remote
  • Location: Offshore
  • Total Experience Required: 4 to 8 years
  • Relevant Experience Required: 3+ years of dedicated offensive security penetration testing and red teaming experience
  • Mandatory Certification: Offensive Security Certified Professional (OSCP) or GIAC Penetration Tester (GPEN)
Job Summary

We are seeking an experienced Penetration Tester to conduct rigorous, multi-vector offensive security assessments against our global network infrastructure, web applications, and cloud environments. The ideal candidate will emulate advanced persistent threat (APT) tactics, discover hidden exploit vulnerabilities, and write technical proof-of-concept reports to help software engineering and infrastructure teams systematically harden corporate defenses.

Key Responsibilities

  • Execute comprehensive network and web application penetration tests, utilizing automated scanning suites alongside manual exploration tactics to expose system vulnerabilities.
  • Conduct realistic red-teaming simulation campaigns, probing corporate defenses, orchestrating advanced social engineering scenarios, and bypassing physical perimeter monitoring configurations.
  • Develop structural custom exploitation scripts (e.g., Python , PowerShell , Bash) to demonstrate vulnerability severity while respecting operational stability guidelines.
  • Triage and evaluate cloud infrastructure entry vectors, assessing multi-tenant environment perimeters, microservice containers, API authentication weaknesses, and misconfigured access permissions.
  • Document and present highly detailed vulnerability disclosure reports, assigning clear impact scoring (CVSS), defining business risk matrices, and detailing step-by-step technical remediation paths.
  • Perform rigorous post-remediation verification sweeps, re-testing patched software frameworks, validated infrastructure updates, and newly implemented defensive logic barriers.
  • Collaborate closely with blue-team defensive operators, providing specific threat behavior inputs to optimize SIEM monitoring rules and security log alerts.
Requirements
  • 4 to 8 years of core cybersecurity technical experience, with 3+ dedicated years actively performing authorized penetration tests within enterprise frameworks.
  • Deep structural understanding of the OWASP Top 10 web/API flaws, Windows/Linux kernel security architectures, privilege escalation techniques, and active directory exploit vectors.
  • Mandatory certification: OSCP or GPEN.
Preferred Qualifications
  • Offensive Security Certified Expert (OSCE) or Advanced Web Attacks and Exploitation (OSWE) credential.
  • Experience testing complex enterprise platforms like Salesforce networks, custom SAP endpoints, or specialized Workday database connectivity pipelines.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Hiring For Penetration Tester - Mumbai
Hiring For Penetration Tester - Mumbai

Saint Gobain • Navi Mumbai

On-site
INR 350,000 - 700,000
Principal Penetration Tester/ Offensive Security Team Lead
Principal Penetration Tester/ Offensive Security Team Lead

BreachLock Inc. • Pune District

On-site
INR 5,000,000 - 7,500,000
Penetration Tester
Penetration Tester

Michael Page • Hyderabad

On-site
INR 2,500,000 - 5,500,000
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Senior Penetration Tester
Senior Penetration Tester

Tsys Global Solutions • Pune District

On-site
INR 900,000 - 1,500,000
Senior Penetration Tester
Senior Penetration Tester

AppSecure Security • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Competitive compensation package
Comprehensive health insurance
Company-sponsored off-sites
+2
Security Engineer - OSCP
Security Engineer - OSCP

TAC Security • Delhi

On-site
INR 1,200,000 - 1,800,000
Penetration Tester Specialist
Penetration Tester Specialist

Tsys Global Solutions • Pune District

On-site
INR 900,000 - 1,300,000
Penetration Tester (SMB)
Penetration Tester (SMB)

BreachLock, Inc. • Dadri

On-site
INR 1,200,000 - 2,400,000
Private Health Insurance
Senior Penetration Testing Consultant
Senior Penetration Testing Consultant

EY • Bengaluru

On-site
INR 1,800,000 - 3,200,000