Senior Associate, Offensive Security

RSM US LLP

Bengaluru

On-site

INR 1,800,000 - 3,200,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

RSM US LLP in Bengaluru, India, is seeking an experienced Application Penetration Tester – Offensive Security Testing (Sr. Associate). You will lead security assessments across Web, API, network and cloud environments, performing red teaming and AI/LLM security testing as required.

You'll collaborate with clients and teams to articulate findings, risks, and remediation strategies, mentoring junior staff and staying current with evolving attacker techniques and security trends.

Qualifications

  • 5+ years of Offensive Security, Penetration Testing, Red Teaming, or related security domains.
  • Advanced expertise in Web & API Security and exploitation techniques.
  • Hands-on experience with network testing, AD attacks, privilege escalation, lateral movement, and post-exploitation.
  • Experience with Red Teaming, Adversary Simulation and MITRE ATT&CK-based techniques.
  • Cloud Security Assessments across AWS, Azure, and/or GCP.
  • Proficient in Python, PowerShell, Bash or JavaScript.
  • Excellent written and verbal communication with senior management and clients.
  • Preferred OSCP, OSEP, OSWE, CRTO/CRTP/CREST or similar certifications.

Responsibilities

  • Lead and conduct security assessments, including Web & API Penetration Testing, Network Penetration Testing, and Application Security Testing
  • Conduct Red Teaming and Adversary Simulation exercises using real-world attack techniques and TTPs
  • Perform Active Directory security assessments, including privilege escalation, lateral movement, and attack-path analysis
  • Conduct Cloud Security Assessments and Penetration Testing across AWS, Azure, and GCP environments
  • Perform Purple Team Exercises and Breach & Attack Simulation (BAS) to assess and improve security controls and detection capabilities
  • Collaborate with clients across different technology environments and clearly articulate technical findings, attack scenarios, risks, and remediation recommendations
  • Stay current with the latest Offensive Security techniques, adversary TTPs, vulnerabilities, AI/LLM security, and emerging technologies
  • Lead and mentor staff on engagements

Skills

Web & API Security
Network Penetration Testing
Red Teaming
MITRE ATT&CK
Cloud Security
Python
PowerShell
Bash
JavaScript
Communication skills

Education

BS in CS/Engineering/Cybersecurity or related field

Tools

Burp Suite
OWASP ZAP
Nessus
Metasploit
Active Directory

Job description

We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, inclusive culture and talent experience and our ability to be compelling to our clients. You’ll find an environment that inspires and empowers you to thrive both personally and professionally. There’s no one like you and that’s why there’s nowhere like RSM.

Application Penetration Tester – Offensive Security Testing (Sr. Associate)
Role Responsibilities
  • Lead and conduct security assessments, including Web & API Penetration Testing, Network Penetration Testing, and Application Security Testing
  • Conduct Red Teaming and Adversary Simulation exercises using real-world attack techniques and TTPs
  • Perform Active Directory security assessments, including privilege escalation, lateral movement, and attack-path analysis
  • Conduct Cloud Security Assessments and Penetration Testing across AWS, Azure, and GCP environments
  • Perform Purple Team Exercises and Breach & Attack Simulation (BAS) to assess and improve security controls and detection capabilities
  • Conduct AI/LLM Security Testing and AI Red Teaming to identify security risks associated with emerging AI technologies
  • Apply offensive security techniques including EDR/AV evasion, Command & Control (C2), privilege escalation, lateral movement, and post-exploitation in authorized testing environments
  • Perform Application Security assessments and Code Reviews as required
  • Collaborate with clients across different technology environments and clearly articulate technical findings, attack scenarios, risks, and remediation recommendations
  • Stay current with the latest Offensive Security techniques, adversary TTPs, vulnerabilities, AI/LLM security, and emerging technologies
  • Lead and foster teamwork and open communication to deliver successful engagements
  • Supervise, mentor, and provide technical guidance to staff working on assigned engagements
Qualifications and Experience
  • BS in Computer Science, Engineering, Cybersecurity, or related field, or equivalent work experience
  • 5+ years of experience in Offensive Security, Penetration Testing, Red Teaming, or related security domains
  • Advanced expertise in Web & API Security, including vulnerability identification and exploitation techniques
  • Hands-on experience with Network Penetration Testing, Active Directory attacks, privilege escalation, lateral movement, and post-exploitation
  • Experience with Red Teaming, Adversary Simulation, and MITRE ATT&CK-based techniques
  • Experience with Cloud Security Assessments across AWS, Azure, and/or GCP
  • Knowledge of Purple Teaming, Breach & Attack Simulation (BAS), and security control validation
  • Experience or understanding of EDR/AV evasion, Command & Control (C2), and post-exploitation techniques
  • Experience with Application Security, SAST/DAST, and Code Review is preferred
  • Exposure to AI/LLM Security Testing and AI Red Teaming is preferred
  • Proficient scripting/programming skills such as Python, PowerShell, Bash, or JavaScript
  • Excellent written and verbal communication skills with the ability to clearly communicate technical findings to senior management and clients
  • Must possess a high degree of integrity and confidentiality and adhere to company policies and security testing best practices
  • Preferred, but not required – relevant certifications such as OSCP, OSEP, OSWE, CRTO, CRTP, CREST, Burp Suite Certified Practitioner, or other relevant Offensive Security certifications

Shift Timing: - Rotational Shift

At RSM, we offer a competitive benefits and compensation package for all our people.We offer flexibility in your schedule, empowering you to balance life's demands, while also maintaining your ability to serve clients.Learn more about our total rewards at https://rsmus.com/careers/india.html.

RSM does not tolerate discrimination and/or harassment based on race; colour; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender (including gender identity and/or gender expression); sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the Indian Armed Forces; Indian Armed Forces Veterans, and Indian Armed Forces Personnel status; pre-disposing genetic characteristics or any other characteristic protected under applicable provincial employment legislation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Kroll • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Cyber Security Strategy, Senior Associate 1
Cyber Security Strategy, Senior Associate 1

RSM US LLP • Gurugram District

On-site
INR 1,500,000 - 2,600,000
Cyber Security Strategy - Senior Associate 1
Cyber Security Strategy - Senior Associate 1

RSM US in India • Gurugram District

On-site
INR 1,800,000 - 2,600,000
Senior Associate 2 - ORM Digital
Senior Associate 2 - ORM Digital

RSM US in India • Hyderabad, Bengaluru

On-site
INR 900,000 - 1,300,000
Senior Associate 2, ORM Digital
Senior Associate 2, ORM Digital

RSM US LLP • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Flexible scheduling
Competitive benefits package
Consultant, Offensive Security
Consultant, Offensive Security

Kroll • Bengaluru

On-site
INR 1,200,000 - 2,400,000
Principal Consultant, Offensive Security
Principal Consultant, Offensive Security

Kroll • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Technology Risk Consulting Associate 2
Technology Risk Consulting Associate 2

RSM US in India • Gurugram District

On-site
INR 600,000 - 1,200,000
Executive - Cyber Defense
Executive - Cyber Defense

BSR & Co • Mumbai

On-site
INR 1,400,000 - 2,300,000
Technology Performance Senior Associate
Technology Performance Senior Associate

RSM US LLP • Bengaluru

On-site
INR 800,000 - 1,500,000
Competitive benefits and compensation
Flexible schedule