Senior, Cybersecurity Penetration Tester

Schneider Electric

Bengaluru

On-site

INR 2,500,000 - 4,500,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Schneider Digital in Bengaluru is seeking a Cybersecurity Penetration Tester to assess security of systems, perform penetration testing across Web, Mobile, API, Cloud and container environments, and provide actionable remediation guidance.

You will work with application security and compliance teams, apply OWASP and SANS methodologies, share findings, and help strengthen security controls while staying abreast of new attack techniques and DevSecOps practices.

Qualifications

  • Experience with pentest standards (OWASP, SANS) and security testing lifecycles.
  • Proven knowledge of web/mobile/API/IoT assessments and cloud security concepts.

Responsibilities

  • Understand project deliverables and application details.
  • Run automated and manual security checks to uncover weaknesses in the system.
  • Propose mitigation steps for identified risks and threats.
  • Provide clear recommendations from a security perspective based on application risk and business context.
  • Work alongside the cybersecurity community and application teams.
  • Explore process, reporting and improvement in techniques.
  • Ability to collaborate with other penetration teams to align knowledge, tools and techniques.

Skills

Web/Mobile/API/Cloud security
Containers security
Security testing & tooling
Automation & scripting
DevSecOps methodologies

Education

BE/MS/MCA in Computer Science/IT
Certifications: OSCP OSCE GPEN GXPN GICSP GWAPT OSWP etc.
Azure/AWS security certifications a plus
CISSP, CEH a plus
Background in Computer Science/IT fields

Job description

Cybersecurity Penetration Tester Schneider Digital is the global IT organization within Schneider Electric. We have, within our Cybersecurity function, an objective to assess the security of our systems, to identify security risks before those materialize. Technical assurance, by means of security testing of the actual system, is crucial so we identify application related issues that need to be addressed.

Cybersecurity Penetration Tester Schneider Digital is the global IT organization within Schneider Electric. We have, within our Cybersecurity function, an objective to assess the security of our systems, to identify security risks before those materialize. Technical assurance, by means of security testing of the actual system, is crucial so we identify application related issues that need to be addressed. This role is part of our DE Penetration Testing unit and will focus on performing penetration testing of those systems, and providing clear guidance as to how to address weaknesses identified. The role holder will be working in collaboration with the applications security and compliance regional managers and other IT specialists, to train in Schneider Electric security policies, processes, and tools.

Responsibilities
  • Understand project deliverables and application details
  • Run automated and manual security checks (not limited to tools) to uncover security weaknesses in the system
  • Propose mitigation steps for identified risks and threats
  • Provide clear recommendations from a security perspective based on understanding of application, application risk and business context, and results of checks performed.
  • Work alongside the cybersecurity community and application teams.
  • Explore process, reporting and improvement in techniques
  • Ability to collaborate with other penetration teams to align knowledge, tools and techniques
Behaviors and Competencies
  • Strong written and verbal communication skills, with a proven ability to communicate with technical staff, as well as project teams, so security risks are understood in business terms
  • Keep pace with standards and technologies related to security
  • Leadership / Act like owners
  • Collaboration / Teamwork
  • Requirements Gathering and Analysis
  • Interpersonal Skills, proactiveness
  • Willing to learn new skills / Learn Every day and desire to succeed and grow
Skills
  • Security – Web, Mobile, API, Cloud and container security, Thick Client, Network, Operating System
  • Applications Development & Delivery
  • Understanding or experience of any of the following is an advantage:
    • Cloud Security Assessment and Security Audits of Cloud Environment
    • Vulnerability Management (Process, Tools and Metrics)
    • NIST Cybersecurity Framework
    • Critical Security Controls (CSC)
  • Expertise in DevSecOps methodologies is also an advantage.
Knowledge
  • Pentest standards and methodologies, OWASP, SANS etc.
  • Subject matter expert in web/mobile/thick client/API/IoT/IIoT assessments
  • Good understanding of server vulnerabilities (Linux, Windows) and hardening
  • Familiarity with cloud platforms, and cloud container security
  • Efficient and effective usage of pentest tools as well as demonstrate less dependency on tools.
  • Experience with automation, scripting (Python, Perl, Ruby, etc.)
  • Proactive interest in emerging technologies (e. g. Offensive AI) and techniques related to penetration testing
  • Basic understanding of AI/ML concepts and Large Language Models (LLMs) and their integration in modern applications
  • Awareness of security risks in AI/LLM-based systems, including prompt injection, data leakage, and API misuse in GenAI applications
  • Ability to translate technical security topics in a business-friendly manner
  • Demonstrable teamwork skills and resourcefulness
  • Virtual Machines Management
Experience
Essential
  • 4+ years of experience in IT security
  • Min 3+ years of experience in penetration testing of Web, Mobile (iOS & Android), API, Thick client & Network.
Desirable
  • Experience with red teams or CTF (Capture the Flag)
  • Experience with reverse engineering
  • Presented exploit POC/ research concepts at forums like exploit-db.
  • Participated in national/ international cybersecurity conferences.
  • DevSecOps implementation and supporting security tooling is desirable (SAST)
Education and Training
  • BE or MS or MCA Computers Science or Information Technology or related fields
  • Tech Computers Science or Information Technology or related fields
  • Certifications - OSCP, OSCE, GPEN, GXPN, GICSP, GWAPT, OSWP, etc.
  • Azure / AWS security certifications is a plus.
  • CISSP, CEH also a plus
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Engineer I, Cybersecurity Testing and Audit
Senior Engineer I, Cybersecurity Testing and Audit

Schneider Electric • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Penetration Tester
Penetration Tester

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 1,200,000 - 2,200,000
Hybrid Working
Senior Penetration Tester
Senior Penetration Tester

Tekskills • Bengaluru

On-site
INR 350,000 - 650,000
Senior Penetration Tester
Senior Penetration Tester

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 2,500,000 - 4,000,000
Hybrid Working
Cyber Security Specialist
Cyber Security Specialist

Muthoot FinCorp (MFL) • Thiruvananthapuram

On-site
INR 900,000 - 1,300,000
Penetration Tester Architect ( VAPT, Android , IOS ) - Naukri.com
Penetration Tester Architect ( VAPT, Android , IOS ) - Naukri.com

Info Edge • Greater Noida, Dadri

On-site
INR 900,000 - 1,200,000
Cyber Security Specialist
Cyber Security Specialist

Muthoot FinCorp (MFL) • India

On-site
INR 1,200,000 - 2,400,000
Penetration Tester
Penetration Tester

Soffit Infrastructure Services (P) Ltd • Ernakulam

On-site
INR 1,200,000 - 1,800,000
Cyber Security Specialist
Cyber Security Specialist

SuperOps • Chennai District

On-site
INR 800,000 - 1,200,000
Hiring For Penetration Tester - Mumbai
Hiring For Penetration Tester - Mumbai

Saint Gobain • Mumbai, Navi Mumbai

On-site
INR 4,000,000 - 8,000,000