Senior Penetration Tester

Tsaaro Consulting Inc.

Bengaluru

On-site

INR 2,000,000 - 3,200,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Tsaaro Consulting Inc. in Bengaluru is seeking a Senior Penetration Tester to lead VAPT engagements across web apps, APIs, mobile apps, networks, cloud, and enterprise infrastructure.

You will identify exploitable vulnerabilities, simulate attacks, and deliver remediation guidance. The role requires strong hands-on testing, experience with OWASP, MITRE ATT&CK, and top security tools, plus mentoring junior testers and contributing to methodologies.

Qualifications

  • 3–6+ years of experience in Penetration Testing, Vulnerability Assessment (VAPT), Offensive Security, Red Teaming, or Cybersecurity Consulting.
  • Strong hands-on experience in web application, API, mobile application, network, cloud, and infrastructure penetration testing.
  • Deep understanding of OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK Framework, PTES, NIST SP 800-115, and common penetration testing methodologies.
  • Hands-on experience with offensive security tools such as Burp Suite Professional,Metasploit, Nmap, Nessus, Wireshark, SQLMap, BloodHound, Impacket, Nuclei, Kali Linux, and similar tools.
  • Experience conducting security assessments across AWS, Microsoft Azure, and Google Cloud Platform.
  • Strong understanding of networking protocols, Windows and Linux security, Active Directory, authentication mechanisms, and secure application architecture.
  • Experience preparing technical penetration testing reports, executive summaries, and remediation guidance for clients.
  • Excellent analytical, problem-solving, stakeholder management, and client communication skills.
  • Professional certifications such as OSCP, OSEP, OSWE, PNPT, GPEN, CEH Practical, CRTO, or equivalent offensive security certifications are highly preferred.
  • A collaborative, research-driven, and solution-oriented mindset with the ability to independently manage multiple client engagements.
  • Work with one of India's fastest-growing privacy and cybersecurity consulting firms.
  • Gain exposure to global clients across diverse industries.
  • Lead advanced penetration testing and offensive security engagements.
  • Accelerate your career with mentorship and leadership opportunities.
  • Hybrid work flexibility.
  • Continuous learning support through certifications and professional development programs.

Responsibilities

  • Lead and execute Vulnerability Assessment and Penetration Testing (VAPT) engagements across web applications, APIs, mobile applications, networks, cloud environments, and enterprise infrastructure.
  • Perform manual penetration testing to identify and validate security vulnerabilities beyond automated vulnerability scans.
  • Conduct security assessments aligned with industry methodologies such as OWASP Testing Guide, PTES, NIST SP 800-115, and MITRE ATT&CK.
  • Identify and exploit vulnerabilities including OWASP Top 10, OWASP API Security Top 10, authentication and authorization flaws, business logic vulnerabilities, insecure configurations, privilege escalation, and infrastructure weaknesses.
  • Perform internal and external network penetration testing, Active Directory assessments, wireless security testing, and cloud security assessments across AWS, Microsoft Azure, and Google Cloud Platform.
  • Execute Red Team assessments, adversary emulation exercises, and attack simulations where required.
  • Validate and prioritize vulnerabilities based on business impact, exploitability, and risk.
  • Prepare detailed technical reports, executive summaries, proof-of-concept documentation, and actionable remediation recommendations.
  • Support clients in vulnerability remediation by performing re-validation testing and security consultations.
  • Mentor junior penetration testers and contribute to the continuous improvement of internal methodologies, tools, automation scripts, and offensive security playbooks.
  • Stay updated on emerging cyber threats, attack techniques, exploit research, and security vulnerabilities to continuously enhance testing methodologies.
  • Collaborate with cross-functional teams to improve secure development practices, strengthen security controls, and enhance clients' overall cybersecurity resilience.

Skills

Penetration Testing
VAPT
Red Teaming
Offensive Security Tools
Cloud Security
OWASP Top 10
MITRE ATT&CK
Report Writing
Client Communication
Certifications

Tools

Burp Suite Pro
Metasploit
Nmap
Nessus
Wireshark
SQLMap
BloodHound
Impacket
Nuclei
Kali Linux

Job description

Join Tsaaro as a Senior Penetration Tester

Hack with Purpose. Strengthen Security. Build CyberResilience.

Are you passionate about offensive security, ethicalhacking, and helping organizations identify and eliminate securityvulnerabilities before attackers can exploit them?

At Tsaaro, we go beyond vulnerability identification—wehelp organizations proactively strengthen their cybersecurity posture throughcomprehensive Vulnerability Assessment and Penetration Testing (VAPT), Red Teamexercises, cloud security assessments, and offensive security consulting. Weare looking for a Senior Penetration Tester who thrives in consultingenvironments, enjoys solving complex security challenges, and can deliverpractical, risk-based security solutions to clients.

At Tsaaro, privacy and cybersecurity are at the heart ofeverything we do. Our team of cybersecurity specialists and privacy consultantsworks closely with organizations to identify vulnerabilities, assess cyberrisks, strengthen security controls, and build resilient cyber defenseprograms.

Our consulting approach focuses on delivering practical,business-aligned cybersecurity solutions that help clients secure criticalassets, reduce cyber risk, achieve compliance, and stay ahead of evolvingthreats.

As a Senior Penetration Tester, you will lead and executeVulnerability Assessment and Penetration Testing (VAPT) engagements across webapplications, APIs, mobile applications, networks, cloud environments, andenterprise infrastructure. You will work closely with clients to identifyexploitable vulnerabilities, simulate real-world attack scenarios, validatesecurity controls, and provide actionable remediation recommendations tostrengthen their overall cybersecurity posture.

Key Responsibilities
  • Conductend-to-end Vulnerability Assessment and Penetration Testing (VAPT) acrossweb applications, APIs, mobile applications, internal and externalnetworks, cloud environments, and enterprise infrastructure.
  • Performmanual penetration testing to identify and validate securityvulnerabilities beyond automated vulnerability scans.
  • Conductsecurity assessments aligned with industry methodologies such as OWASPTesting Guide, PTES, NIST SP 800-115, and MITRE ATT&CK.
  • Identifyand exploit vulnerabilities including OWASP Top 10, OWASP API Security Top10, authentication and authorization flaws, business logicvulnerabilities, insecure configurations, privilege escalation, andinfrastructure weaknesses.
  • Performinternal and external network penetration testing, Active Directoryassessments, wireless security testing, and cloud security assessmentsacross AWS, Microsoft Azure, and Google Cloud Platform.
  • ExecuteRed Team assessments, adversary emulation exercises, and attacksimulations where required.
  • Validateand prioritize vulnerabilities based on business impact, exploitability,and risk.
  • Preparedetailed technical reports, executive summaries, proof-of-conceptdocumentation, and actionable remediation recommendations.
  • Supportclients in vulnerability remediation by performing re-validation testingand security consultations.
  • Mentorjunior penetration testers and contribute to the continuous improvement ofinternal methodologies, tools, automation scripts, and offensive securityplaybooks.
  • Stayupdated on emerging cyber threats, attack techniques, exploit research,and security vulnerabilities to continuously enhance testingmethodologies.
  • Collaboratewith cross-functional teams to improve secure development practices,strengthen security controls, and enhance clients' overall cybersecurityresilience.
Requirements
  • 3–6+years of experience in Penetration Testing, Vulnerability Assessment(VAPT), Offensive Security, Red Teaming, or Cybersecurity Consulting.
  • Stronghands-on experience in web application, API, mobile application, network,cloud, and infrastructure penetration testing.
  • Deepunderstanding of OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CKFramework, PTES, NIST SP 800-115, and common penetration testingmethodologies.
  • Hands-onexperience with offensive security tools such as Burp Suite Professional,Metasploit, Nmap, Nessus, Wireshark, SQLMap, BloodHound, Impacket, Nuclei,Kali Linux, and similar tools.
  • Experienceconducting security assessments across AWS, Microsoft Azure, and GoogleCloud Platform.
  • Strongunderstanding of networking protocols, Windows and Linux security, ActiveDirectory, authentication mechanisms, and secure application architecture.
  • Experiencepreparing technical penetration testing reports, executive summaries, andremediation guidance for clients.
  • Excellentanalytical, problem-solving, stakeholder management, and clientcommunication skills.
  • Professionalcertifications such as OSCP, OSEP, OSWE, PNPT, GPEN, CEH Practical, CRTO,or equivalent offensive security certifications are highly preferred.
  • Acollaborative, research-driven, and solution-oriented mindset with theability to independently manage multiple client engagements.
  • Workwith one of India's fastest-growing privacy and cybersecurity consultingfirms.
  • Gainexposure to global clients across diverse industries.
  • Leadadvanced penetration testing and offensive security engagements.
  • Accelerateyour career with mentorship and leadership opportunities.
  • Hybridwork flexibility.
  • Continuouslearning support through certifications and professional developmentprograms.
From the Tsaaro Team

\"At Tsaaro, we believe the strongest securityprograms are built by continuously challenging them. If you're passionate aboutoffensive security, uncovering hidden risks, and helping organizationsstrengthen their cyber resilience, we'd love to have you on our team.\"

Ready to Advance Your Cyber Security Career?
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Penetration Tester
Senior Penetration Tester

Tsaaro Solutions Pvt. Ltd. • Bengaluru

Hybrid
INR 1,400,000 - 2,200,000
Hybrid work
Learning & certification support
Senior Penetration Tester
Senior Penetration Tester

Tsaaro People Consulting • Bengaluru

Hybrid
INR 1,500,000 - 2,800,000
Hybrid work flexibility
Global client exposure
Mentorship opportunities
+1
Senior VAPT Engineer – Cybersecurity
Senior VAPT Engineer – Cybersecurity

Art Technology and Software • Ernakulam

On-site
INR 1,500,000 - 2,600,000
Hiring For Penetration Tester - Mumbai
Hiring For Penetration Tester - Mumbai

Saint Gobain • Mumbai, Navi Mumbai

On-site
INR 4,000,000 - 8,000,000
Senior Penetration Testing Consultant
Senior Penetration Testing Consultant

EY • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Kroll • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Senior Penetration Tester
Senior Penetration Tester

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 2,500,000 - 4,000,000
Hybrid Working
Sr. Consultant/Lead Consultant – Application Penetration Tester (APT)
Sr. Consultant/Lead Consultant – Application Penetration Tester (APT)

Talpro • Mumbai

On-site
INR 1,674,000 - 2,567,000
Senior Penetration Tester
Senior Penetration Tester

AppSecure Security • Bengaluru Urban

Remote
INR 1,500,000 - 2,100,000
Competitive compensation package
Comprehensive health insurance
Company-sponsored off-sites
+2
Cyber Penetration Tester Senior
Cyber Penetration Tester Senior

Baker Tilly • Gurugram District, Bengaluru

Hybrid
INR 1,500,000 - 2,500,000