Security Pen tester

Infios

Bengaluru

On-site

INR 3,000,000 - 5,500,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Infios is building a dedicated RED Team to strengthen the security of our SaaS platform. As a Penetration Tester, you will conduct internal offensive security assessments across our web applications, APIs, cloud environments, and emerging AI/LLM-based features.

You will identify, exploit, and document vulnerabilities to help the organization stay ahead of modern adversaries. You will work with engineering and product teams to provide remediation guidance, develop PoCs, and contribute to threat

Qualifications

  • Hands-on penetration testing with focus on web apps, APIs and cloud.
  • Solid understanding of OWASP Top 10 and exploitation techniques.
  • Experience testing REST and GraphQL APIs in practice.
  • Familiarity with cloud-hosted apps and modern auth mechanisms (OAuth, JWT, SSO, SAML).
  • Ability to perform manual exploitation beyond automated tools.

Responsibilities

  • Conduct in-depth penetration tests on web applications, APIs, microservices, and internal SaaS components.
  • Perform manual vulnerability discovery and exploitation following OWASP methodologies.
  • Simulate adversarial attack scenarios and participate in RED Team exercises.
  • Conduct cloud-focused penetration tests and configuration reviews (AWS, OCI and Azure).
  • Test LLM/AI features for prompt injection and data leakage; develop PoCs when needed.
  • Develop clear remediation guidance for engineering teams and stakeholders.

Skills

Penetration testing
OWASP Top 10
REST & GraphQL APIs
Cloud security testing
Web application security

Education

CEH
OSCP
OSWE
AWS/Azure security certifications

Tools

Burp Suite Pro
Nmap
Nikto
SQLMap
Postman/Insomnia
Metasploit

Job description

If you are looking for a meaningful career where people work and act with passion, rethink the existing and always strive to find the best solution - you have come to the right place. We develop future technologies to relentlessly make supply chains better.

We are a leader in supply chain software solutions, helping organizations streamline operations, reduce costs, and improve efficiency.

Job Summary

We are building a dedicated RED Team to strengthen the security of our SaaS platform. As a Penetration Tester, you will conduct internal offensive security assessments across our web applications, APIs, cloud environments, and emerging AI/LLM-based features. You will identify, exploit, and document vulnerabilities to help the organization stay ahead of modern adversaries.

What a Day In The Life Looks Like
  • Conduct in-depth penetration tests on web applications, APIs, microservices, and internal SaaS components.
  • Perform manual vulnerability discovery and exploitation following OWASP methodologies.
  • Simulate adversarial attack scenarios and participate in RED Team exercises.
  • Conduct cloud-focused penetration tests and configuration reviews (AWS, OCI and Azure).
  • Test LLM/AI features for prompt injection, jailbreaking, data leakage, model manipulation, and other emerging threats.
  • Develop custom proof-of-concept exploits where applicable.
  • Work closely with engineering and product teams to provide clear remediation guidance.
Security Automation & Tools
  • Use and customize security testing tools (Burp Suite, ZAP, Nmap, SQLMap, etc.).
  • Develop scripts or small tools for automation or exploitation (Python, Bash, PowerShell, etc.).
  • Effectively use AI tools (Microsoft Copilot, Claude etc.) to accelerate testing, generate payloads, summarize findings, and produce documentation.
Documentation & Reporting
  • Create clear, detailed technical reports with reproduction steps and exploit evidence.
  • Present findings to technical and leadership teams.
  • Contribute to threat models and risk assessments.
What You Bring To The Team
  • 4+ years of hands‑on experience in cybersecurity, with a focus on penetration testing.
  • Strong understanding of OWASP Top 10 and practical experience exploiting them in real‑world applications.
  • Experience testing REST and GraphQL APIs.
  • Solid understanding of web technologies (HTML, JavaScript, SQL, authentication mechanisms, etc.).
  • Proven experience performing manual exploitation (not just tool‑based scanning).
  • Experience testing cloud‑hosted applications and infrastructure (AWS, OCI and Azure).
  • Knowledge of modern authentication (OAuth, JWT, SSO, SAML).
AI/LLM Security (Preferred, Not Mandatory)
  • Experience testing AI/LLM‑powered features.
  • Knowledge of prompt injection, jailbreaks, RAG attacks, model extraction, data leakage vectors.
Tools & Methodologies
  • Proficiency with:
    • Burp Suite Pro
    • Nmap
    • Nikto
    • SQLMap
    • Postman/Insomnia
    • Metasploit
    • SAST/DAST tools (optional)
  • Ability to leverage AI/Copilot tools in daily workflow (payload generation, code review, exploit crafting).
Soft Skills
  • Strong analytical and problem‑solving skills.
  • Ability to work independently and in a fast‑paced RED Team environment.
  • Excellent written and verbal communication skills.
  • Curiosity‑driven mindset with a passion for offensive security.
Preferred Certifications (Nice To Have)
  • CEH, OSCP, OSWE, Burp Suite Practitioner, eWPT, eCPPT
  • Cloud certifications (Azure AZ‑500, AWS Security Specialty)
Why join us?

At Infios, we're not just looking for employees; we're looking for partners in innovation, growth, and purpose. Meeting you where you are to create the future you need is at the core of who we are and what we do. Whether you're at the beginning of your career or a seasoned expert, we meet you on your journey, equipping you with the tools and opportunities to build the future you envision. Together, we will relentlessly work toward one common goal - making supply chains better.

We believe the future is better when supply chains work better.

We are an equal‑opportunity employer and committed to inclusion in the workplace.

At Infios, we believe that inclusion is a fundamental cornerstone of our success. We are committed to creating a safe and welcoming environment where every individual’s unique experiences and perspectives are valued—whether they look, think, move, believe, or love differently.

All qualified applicants will receive consideration for employment without regard to race, color, ethnicity, national origin, sex, sexual orientation, gender identity, marital status, pregnancy, religion, age, disability, veteran status, genetic information, or any other characteristic protected by law.

Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this role. If you require assistance or accommodation due to a disability during the recruiting process, please let us know at jobs@infios.com

Disclaimer: This job advertisement is not designed to cover a comprehensive listing of all duties or responsibilities that are required for this job. Please note that any salary information is a general guideline only. Individual compensation will be determined by various factors such as the scope and responsibilities of the position, experience, education, skills, location, and market and business considerations. Applications must be submitted via our career site.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Pen tester
Security Pen tester

Infios US, Inc. • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Cyderes • Bengaluru

Hybrid
INR 1,800,000 - 2,800,000
Medical Insurance
Life Insurance
Retirement Match Program
+7
Senior Penetration Tester
Senior Penetration Tester

AppSecure Security • Bengaluru Urban

Remote
INR 1,500,000 - 2,100,000
Competitive compensation package
Comprehensive health insurance
Company-sponsored off-sites
+2
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

The Herjavec Group US • Bengaluru

Hybrid
INR 1,800,000 - 3,200,000
Hybrid Work Model
Medical Insurance - Employee + depend.
Life Insurance
+3
Associate Cybersecurity Consultant
Associate Cybersecurity Consultant

Security Brigade • Mumbai

Hybrid
INR 800,000 - 1,200,000
Competitive salary aligned to experience
Hybrid + remote-friendly
Sponsorship for offensive security certifications
+2
Security Tester
Security Tester

Paramount Computer Systems LLC • Coimbatore District

On-site
INR 900,000 - 1,300,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Cacheflow • Bengaluru

Hybrid
INR 1,500,000 - 2,200,000
Medical Insurance
Life Insurance
Hybrid Work Model
+2
4486-Security Engineer II
4486-Security Engineer II

Innovaccer • Dadri

On-site
INR 1,500,000 - 2,500,000
Leaves up to 40 days
Parental leave
Sabbatical
+3
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

LSEG • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Security Engineer
Senior Security Engineer

Delta6Labs FinTech Pvt Ltd • Dadri

On-site
INR 1,500,000 - 2,500,000