Do you love a career where you Experience , Grow & Contribute at the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you.
Learn how we are redefining the meaning of work , and be a part of the team raved by Clients, Job-seekers and Employees.
If you are a Penetration Testing Senior Consultant looking for excitement, challenge and stability in your work, then you would be glad to come across this page.
We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.
Check if you are up for maximizing your earning/growth potential, leveraging our Disruptive Talent Solution.
Role: Penetration Testing Senior Consultant
Work Mode: Hybrid
Type: Contract to Hire
Notice Period:Immediate Joiners
Requirements
As a Penetration Testing Senior Consultant , you will lead the execution of offensive security engagements and help clients identify, validate, and remediate security vulnerabilities across their digital ecosystem.
You will work across application, API, mobile, thick-client, network, cloud, and enterprise infrastructure environments while collaborating with technical and business stakeholders to translate security findings into actionable business risk and remediation recommendations.
Key Responsibilities
- Lead penetration testing workstreams across web applications, APIs, mobile, thick-client, network, cloud, and infrastructure environments .
- Design test plans and execute manual and automated security assessments .
- Identify, validate, exploit, and document security vulnerabilities.
- Perform manual testing for vulnerabilities including:
- SQL Injection / Blind SQL Injection
- XSS and CSRF
- XXE
- SSRF
- Insecure Deserialization
- HTTP Request Smuggling
- Authentication & Authorization weaknesses
- Business Logic vulnerabilities
- Assess OAuth 2.0, OpenID Connect, session management, identity, and access controls .
- Conduct secure code reviews using OWASP Secure Coding Practices or comparable methodologies.
- Perform application security architecture reviews and threat modeling .
- Conduct vulnerability assessments across application, infrastructure, cloud, mobile, and enterprise environments.
- Use industry-standard security testing tools such as Burp Suite, Fiddler, Wireshark, Nmap, Metasploit, Nessus, Qualys, Tenable, Veracode, Frida, Apktool, JADX, dnSpy, and IDA Pro .
- Develop scripts and automation using Python, PowerShell, Bash, or similar technologies to improve reconnaissance, testing, evidence collection, and reporting.
- Support purple team, red team, adversarial simulation, and threat-informed testing activities.
- Map attack scenarios and findings to MITRE ATT&CK and relevant threat behaviors.
- Coordinate with application, infrastructure, cloud, development, and security operations teams for remediation and retesting.
- Prepare detailed technical reports, executive summaries, risk-based findings, remediation recommendations, and client presentations.
- Translate technical vulnerabilities into business-relevant risk statements and prioritized remediation plans.
- Support engagement planning, estimation, proposal development, solution development, and identification of follow-on opportunities.
- Mentor junior team members and review technical deliverables.
- Provide technical and professional feedback to team members.
- Prepare daily, weekly, quarterly, and annual status reports and remediation tracking materials.
- Respond to ad-hoc research, reporting, and technical requests from management and clients.
- Adhere to internal security requirements and Deloitte policies.
Must-Have Skills & Experience
- 7+ years of hands-on cybersecurity experience in penetration testing, application security, cyber risk, vulnerability assessment, or related technical security roles.
- Proven experience conducting penetration testing across multiple domains:
- Web Applications
- APIs
- Mobile Applications
- Thick-Client Applications
- Networks
- Cloud
- Enterprise Infrastructure
- Strong knowledge of OWASP Top 10 and application security vulnerabilities.
- Strong hands-on experience with manual vulnerability assessment and exploitation.
- Strong understanding of:
- OAuth 2.0
- OpenID Connect
- Identity Management
- Session Management
- Access Control
- Experience with secure code reviews .
- Strong hands-on experience with manual penetration testing combined with automated security tools.
Proficiency with tools such as:
Burp Suite, Fiddler, Wireshark, Nmap, Metasploit, Nessus, Qualys, Tenable, Veracode, Frida, Apktool, JADX, dnSpy, IDA Pro or equivalent.
- Strong understanding of web application architecture, including frontend, backend, databases, APIs, application servers, and middleware .
- Experience with application security architecture assessment and threat modeling.
- Understanding of basic reverse engineering and memory analysis concepts.
- Strong understanding of networking protocols including TCP/IP, DNS, HTTP/HTTPS, SMB, and LDAP .
- Familiarity with CVE and CVSS .
- Excellent technical documentation and report-writing skills.
- Strong analytical, problem-solving, prioritization, and stakeholder-management skills.
At least one relevant cybersecurity certification such as:
OSCP, OSWP, GPEN, GWAPT, BSCP, OSWE, CISSP, or CREST certification.
Good-to-Have Skills
- Application, infrastructure, cloud, mobile, and microservices security assessment experience.
- Experience testing AI-enabled applications, LLM integrations, APIs, AI agents, or related systems .
- Red Team, Purple Team, breach attack simulation, or adversary emulation experience.
- Knowledge of:
- MITRE ATT&CK
- Cyber Kill Chain
- SANS Top 25
- Threat-informed penetration testing
- Experience with offensive security tools such as Cobalt Strike, Sliver, BloodHound, Empire, Metasploit, Nmap, Qualys, and Tenable .
- Knowledge of Active Directory security, privilege escalation, lateral movement, identity attacks, and enterprise misconfigurations .
- Experience assessing AWS, Azure, or GCP environments, including IAM, storage, compute, networking, containers, and Kubernetes.
- Familiarity with security monitoring platforms such as Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, Splunk, QRadar, and ArcSight .
- Working knowledge of malware analysis, reverse engineering, binary analysis, exploit development, or memory analysis .
- Security automation and scripting experience using Python, PowerShell, Bash, or similar languages .
- Ability to translate threat intelligence into realistic and controlled attack scenarios.
- Experience presenting security findings to both technical and executive audiences.
- Security research, publications, blogs, open-source projects, conference presentations, or CVEs.
- Preferred certifications: OSWE, OSEP, OSED, OSCE3, CRTO, GXPN, OSEE, AWS Security Specialty, SABSA, or CREST offensive security certifications .
- Familiarity with NIST, PCI DSS, HIPAA, GDPR , and other relevant cybersecurity/privacy standards.
- Strong written and verbal English communication skills.
- Strong interest in continuous learning and developing new offensive security techniques.