Senior Engineer - Penetration Tester

Rakuten Kobo Inc.

Bengaluru

On-site

INR 4,500,000 - 7,500,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Rakuten Kobo Inc. is seeking a seasoned Senior Penetration Tester to perform advanced offensive security assessments across web, mobile, API, cloud, AI/ML, and telecom environments in Bengaluru/Indore.

The role emphasizes identifying complex vulnerabilities, validating exploitability, and guiding engineering teams to strengthen security posture. You will conduct source code reviews, secure design reviews, and architecture-level assessments, while developing PoCs and detailed remediation

Qualifications

  • 10+ years of hands-on penetration testing and application security experience.
  • Strong expertise across web, mobile, API, cloud, infrastructure and AI security testing.
  • Experience with Burp Suite, Kali Linux, Metasploit, Nessus, Nmap, and BloodHound.
  • Proficient in Python, JavaScript, Bash and PowerShell.
  • Familiarity with AWS/Azure/GCP and Kubernetes/Docker.

Responsibilities

  • Perform advanced penetration testing and offensive security assessments across web, mobile, API, cloud, AI/ML and telecom environments.
  • Identify vulnerabilities, validate exploitability, support red team activities, and provide remediation guidance.
  • Conduct source code reviews, secure design reviews, and architecture-level security assessments.
  • Develop PoCs, reports, and actionable remediation recommendations; re-test closures.
  • Research emerging attack techniques and contribute to automation and security testing initiatives.

Skills

Penetration testing
Web security
Mobile security
Cloud security
AI/ML security
Scripting languages

Tools

Burp Suite
Kali Linux
Metasploit
Nessus
Nmap
BloodHound

Job description

Job Description: Job Title: Senior Penetration Tester(Sr. Penetration Tester) Department: Security Assurance Reports To: Senior Manager, Security Assurance Section Location: Bangalore or Indore, India

About the Team/Department: At Rakuten Mobile Security Assurance, you will help secure one of the world's most advanced cloud-native telecom networks, protecting millions of customers across digital, mobile, cloud, and AI-driven services. You will work on cutting-edge offensive security challenges spanning 4G/5G telecom platforms, cloud-native infrastructure, applications, APIs, AI/ML systems, and emerging technologies. We offer an environment where innovation is encouraged, continuous learning is supported, and security experts are empowered to make a direct business impact. You will have the opportunity to work alongside industry-leading engineers, build next-generation security capabilities, leverage AI to transform security testing, and contribute to protecting critical telecommunications infrastructure at scale. If you are passionate about offensive security, enjoy solving complex technical challenges, and want to shape the future of cybersecurity in the AI era, we would love to hear from you.

Position Summary Perform advanced penetration testing and offensive security assessments across Rakuten Mobile's web, mobile, API, cloud, AI/ML, and telecom environments. The role focuses on identifying complex security vulnerabilities, validating exploitability, supporting red team activities, and helping engineering teams strengthen the organization's security posture.

Key Responsibilities
  • Conduct manual and automated penetration testing of web applications, mobile applications, APIs, cloud platforms, and network infrastructure.
  • Perform security assessments of AI/ML applications, LLM-based systems, AI agents, RAG implementations, and MLOps pipelines.
  • Identify vulnerabilities such as prompt injection, insecure model integrations, data leakage, model manipulation, and AI supply chain risks.
  • Execute security testing of telecom systems, including BSS/OSS applications, eSIM platforms, subscriber management systems, mobile network services, and internet-facing telecom applications.
  • Support red team exercises, adversary emulation engagements, attack path analysis, and exploit validation.
  • Conduct source code reviews, secure design reviews, and architecture-level security assessments when required.
  • Develop proof-of-concepts, create detailed technical reports, and provide actionable remediation recommendations.
  • Validate remediation fixes and perform security re-testing to confirm closure.
  • Research emerging attack techniques, exploit methodologies, AI-assisted testing methods, and offensive security tools.
  • Contribute to automation initiatives and continuous security validation capabilities.
Required Qualifications
  • 10+ years of hands-on penetration testing and application security experience.
  • Strong expertise in web, mobile, API, cloud, infrastructure, and AI security testing.
  • Experience with Burp Suite, Kali Linux, Metasploit, BloodHound, Nmap, Nessus, and modern offensive security frameworks.
  • Knowledge of programming and scripting languages such as Python, JavaScript, Bash, and PowerShell.
  • Familiarity with cloud platforms such as AWS, Azure, or GCP and containerized environments such as Kubernetes and Docker.
Preferred Qualifications
  • Experience with telecom technologies, mobile core networks, BSS/OSS systems, and cloud-native telecom applications is preferred.
  • Preferred certifications: OSCP, CRTP, CRTO, OSEP, OSWE, GPEN, GXPN or equivalent certifications.
Nice-to-Have Expertise
  • AI/LLM security testing and adversarial machine learning.
  • Red team operations and advanced exploit development.
  • Cloud and Kubernetes security assessments.
  • 5G / telecom security testing and BSS/OSS security validation.
  • Bug bounty, vulnerability research, and AI-assisted penetration testing.
Core Competencies
  • Advanced Offensive Security - Conducts complex manual penetration tests, exploit validation, and attack-path analysis.
  • Application and API Security - Assesses web, mobile, API, source-code, and application architecture risks.
  • Cloud and Infrastructure Security - Tests AWS/Azure/GCP, Kubernetes, containers, networks, identity systems, and configurations.
  • AI/ML Security Testing - Evaluates LLMs, AI agents, RAG solutions, MLOps pipelines, and AI supply-chain risks.
  • Telecom Security Expertise - Understands 4G/5G, BSS/OSS, eSIM, subscriber platforms, and cloud-native telecom environments.
  • Red Teaming and Adversary Emulation - Applies realistic attacker techniques and supports advanced offensive-security exercises.
  • Security Automation and Scripting - Uses Python, JavaScript, Bash, or PowerShell to automate testing and validation.
  • Analytical Problem-Solving - Investigates complex systems, prioritizes exploitable risks, and develops practical proofs of concept.
  • Risk Communication and Reporting - Clearly explains technical findings, business impact, and actionable remediation to technical and nontechnical stakeholders.
  • Collaboration and Technical Leadership - Works effectively with engineering teams, mentors others, and drives remediation through closure.
  • Continuous Learning and Innovation - Tracks emerging attack techniques, vulnerabilities, tools, and AI-assisted testing methods.
  • Professional Ethics and Accountability - Handles sensitive information responsibly and performs testing within authorized scope.

undefined Rakuten Symphony is reimagining telecom, changing supply chain norms and disrupting outmoded thinking that threatens the industry’s pursuit of rapid innovation and growth. Based on proven modern infrastructure practices, its open interface platforms make it possible to launch and operate advanced mobile services in a fraction of the time and cost of conventional approaches, with no compromise to network quality or security. Rakuten Symphony has operations in Japan, the United States, Singapore, India, South Korea, Europe, and the Middle East Africa region. For more information, visit: https://symphony.rakuten.com Building on the technology Rakuten used to launch Japan’s newest mobile network, we are taking our mobile offering global. To support our ambitions to provide an innovative cloud-native telco platform for our customers, Rakuten Symphony is looking to recruit and develop top talent from around the globe. We are looking for individuals to join our team across all functional areas of our business – from sales to engineering, support functions to product development. Let’s build the future of mobile telecommunications together!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Engineer, Offensive Security
Staff Engineer, Offensive Security

Rakuten Kobo Inc. • Bengaluru

On-site
INR 4,000,000 - 8,000,000
Penetration Tester
Penetration Tester

Rakuten Symphony • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Senior Engineer - Penetration Tester
Senior Engineer - Penetration Tester

Rakuten Symphony • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Technical Lead IPTX
Technical Lead IPTX

Rakuten Kobo Inc. • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Senior Specialist, Security Operation
Senior Specialist, Security Operation

Rakuten Kobo Inc. • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Specialist, Linux Platform Engineer
Senior Specialist, Linux Platform Engineer

Rakuten Kobo Inc. • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Senior Engineer - Penetration Tester
Senior Engineer - Penetration Tester

Rakuten Asia Pte Ltd • Bengaluru, Indore District

On-site
INR 3,500,000 - 6,500,000
Technical Lead, Software Engineering
Technical Lead, Software Engineering

Rakuten Kobo Inc. • Bengaluru

On-site
INR 4,000,000 - 8,000,000
Specialist, Core Network AI & Automation
Specialist, Core Network AI & Automation

Rakuten Kobo Inc. • India

On-site
INR 3,500,000 - 6,000,000
Senior Engineer 2 , Packet Core
Senior Engineer 2 , Packet Core

Rakuten Asia Pte Ltd • Bengaluru

On-site
INR 900,000 - 1,400,000