Security Engineer - OSCP

TAC Security

Delhi

On-site

INR 1,200,000 - 1,800,000

Full time

34 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

TAC Security is seeking a highly skilled Security Engineer – OSCP Certified in Delhi to join our offensive security team. You will conduct comprehensive penetration testing across web apps, APIs, mobile apps, networks, and cloud environments with a strong focus on manual testing and practical exploitation.

Responsibilities include identifying vulnerabilities, validating exploits, and delivering actionable remediation guidance to clients and internal teams.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
  • OSCP certification is mandatory.
  • 3–7+ years of hands-on experience in penetration testing, VAPT, offensive security, or application security.
  • Strong practical knowledge of API Security Testing, Active Directory Security, Vulnerability Assessment, OWASP Top 10, CVSS.
  • Ability to write basic automation/exploitation scripts using Python, Bash, or PowerShell.
  • Excellent analytical, troubleshooting, documentation, and communication skills.

Responsibilities

  • Perform end-to-end Vulnerability Assessment and Penetration Testing (VAPT) across applications and infrastructure.
  • Perform advanced web application and API security testing aligned with OWASP Top 10.
  • Conduct external and internal network penetration testing and assess security weaknesses.
  • Apply OSCP-level penetration-testing techniques; exploit, pivot, and document attack paths.
  • Prepare detailed penetration-testing reports with vulnerability descriptions, severity, evidence, and remediation recommendations.
  • Stay updated on emerging vulnerabilities, CVEs, and exploitation techniques.

Skills

Penetration testing
Vulnerability assessment
Offensive security
Application security
API security testing
Active Directory security
OWASP Top 10
CVSS
Automation scripting (Python/Bash/PS)
Networking fundamentals
OSCP certification

Education

Bachelor's/Master's in CS/IT/Cybersecurity

Tools

Burp Suite
Nmap
Nessus
Wireshark
BloodHound
Impacket
SQLMap
Nikto
Hydra
John the Ripper/Hashcat

Job description

TAC Security is looking for a highly skilled Security Engineer – OSCP Certified with strong hands-on expertise in penetration testing, vulnerability assessment, application security, network security, and offensive security.

The Security Engineer will be responsible for identifying, validating, and demonstrating security vulnerabilities across web applications, APIs, mobile applications, networks, cloud environments, and infrastructure. The role requires a strong offensive-security mindset, practical exploitation skills, and the ability to provide actionable remediation guidance to clients and internal teams.

Key Responsibilities

1. Vulnerability Assessment & Penetration Testing

  • Perform end-to-end Vulnerability Assessment and Penetration Testing (VAPT) across applications and infrastructure.
  • Conduct manual penetration testing rather than relying solely on automated scanning tools.
  • Identify, validate, exploit, and document security vulnerabilities.
  • Perform network and infrastructure penetration testing across internal and external environments.
  • Conduct security testing of web applications, APIs, mobile applications, and cloud-based environments.
  • Perform vulnerability verification and retesting after remediation.
  • Evaluate vulnerabilities based on technical severity, exploitability, and potential business impact.

2. Web Application & API Security

  • Perform advanced web application penetration testing aligned with OWASP Top 10 and relevant testing methodologies.
  • Test for vulnerabilities including SQL Injection, XSS, SSRF, IDOR, authentication and authorization weaknesses, insecure deserialization, file-upload vulnerabilities, business-logic flaws, and security misconfigurations.
  • Conduct API security assessments covering REST and other API architectures.
  • Identify complex authorization, authentication, session-management, and business-logic vulnerabilities.

3. Network & Infrastructure Security

  • Conduct external and internal network penetration testing.
  • Perform network enumeration, service discovery, vulnerability analysis, exploitation, and privilege escalation.
  • Assess Windows and Linux environments for security weaknesses.
  • Conduct Active Directory security assessments and identify privilege-escalation and lateral-movement opportunities.
  • Evaluate firewall configurations, exposed services, network segmentation, and infrastructure security controls.

4. Offensive Security & Exploitation

  • Apply OSCP-level penetration-testing techniques in real-world environments.
  • Perform manual exploitation, privilege escalation, pivoting, lateral movement, and post-exploitation activities within approved scopes.
  • Develop or modify scripts and proof-of-concept exploits when required.
  • Use offensive-security techniques responsibly and strictly within authorized testing environments.
  • Maintain detailed evidence and attack paths throughout engagements.

5. Security Tools & Technologies

Hands-on experience with tools such as:

  • Burp Suite Professional
  • Nmap
  • Nessus
  • Wireshark
  • BloodHound
  • Impacket
  • SQLMap
  • Nikto
  • Hydra
  • John the Ripper/Hashcat

Candidates should understand the underlying techniques and be capable of performing manual validation rather than depending exclusively on tools.

6. Reporting & Remediation

  • Prepare detailed and professional penetration-testing reports containing vulnerability descriptions, severity, evidence, proof of concept, business impact, and remediation recommendations.
  • Assign severity using appropriate methodologies such as CVSS.
  • Conduct technical walkthroughs with customers, developers, security teams, and management.
  • Work closely with engineering teams to explain vulnerabilities and recommend practical remediation.
  • Perform remediation validation and closure testing.

7. Research & Continuous Improvement

  • Stay updated on emerging vulnerabilities, CVEs, exploitation techniques, attack methodologies, and cybersecurity threats.
  • Research new offensive-security techniques and tools.
  • Contribute to internal security methodologies, testing checklists, knowledge bases, automation, and security research.
  • Participate in internal knowledge-sharing and technical training sessions.

Required Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
  • OSCP (Offensive Security Certified Professional) certification is mandatory.
  • 3–7+ years of hands-on experience in penetration testing, VAPT, offensive security, or application security.
  • Strong practical knowledge of:
  • API Security Testing
  • Active Directory Security
  • Vulnerability Assessment
  • OWASP Top 10
  • CVSS
  • Strong understanding of TCP/IP, DNS, HTTP/HTTPS, firewalls, VPNs, proxies, authentication protocols, and network architectures.
  • Ability to write basic automation/exploitation scripts using Python, Bash, or PowerShell.
  • Excellent analytical, troubleshooting, documentation, and communication skills.

Preferred Qualifications

Additional certifications such as OSWE, OSEP, CRTP/CRTE, PNPT, GPEN, GWAPT, CEH, or eJPT would be advantageous.

Experience in one or more of the following would also be valuable: cloud penetration testing across AWS/Azure/GCP, mobile application security, source-code review, DevSecOps/AppSec, red teaming, threat modeling, or secure-code review.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Consultant
Application Security Consultant

SecurityBoat Cybersecurity Solutions Private Limited • Mumbai

On-site
INR 1,200,000 - 2,200,000
Competitive compensation
Specialized cybersecurity team
Professional development
Penetration Testing Senior Consultant
Penetration Testing Senior Consultant

Alignity Solutions • Hyderabad

Hybrid
INR 1,800,000 - 3,000,000
Hybrid work
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Senior Penetration Tester
Senior Penetration Tester

Jobtailor • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Application Security Engineer
Application Security Engineer

Kyndryl • Dadri, Greater Noida

On-site
INR 2,500,000 - 4,500,000
Application Security Analyst
Application Security Analyst

Zs Associates • Pune District

On-site
INR 600,000 - 1,000,000
Sr. Security Consultant
Sr. Security Consultant

Eventussecurity • Navi Mumbai

On-site
INR 600,000 - 1,000,000
Sr Security Engineer
Sr Security Engineer

Ankercloud GmbH • Bengaluru

On-site
INR 1,400,000 - 2,200,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Jobtailor • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Senior Penetration Tester
Senior Penetration Tester

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 2,500,000 - 4,000,000
Hybrid Working