Senior Penetration Tester

Tsaaro Solutions Pvt. Ltd.

Bengaluru

Hybrid

INR 1,400,000 - 2,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work
Learning & certification support

Job summary

Tsaaro Solutions Pvt. Ltd. is seeking a Senior Penetration Tester to lead VAPT engagements across web apps, APIs, mobile apps, networks, and cloud environments. You will simulate real-world attacks, validate controls, and provide remediation guidance to clients.

You will also mentor junior testers, help advance methodologies, and stay updated on evolving threats. This role offers hybrid work flexibility and exposure to global clients.

Qualifications

  • 3-6+ years of experience in Penetration Testing, Vulnerability Assessment, Offensive Security, Red Teaming, or Cybersecurity Consulting.
  • Strong hands-on experience in web application, API, mobile application, network, cloud, and infrastructure penetration testing.
  • Deep understanding of OWASP Top 10, MITRE ATT&CK, PTES, NIST SP 800-115.
  • Experience conducting security assessments across AWS, Azure, and Google Cloud Platform.
  • Strong understanding of networking protocols, Windows and Linux security, Active Directory, and secure application architecture.
  • Experience preparing technical penetration testing reports, executive summaries, and remediation guidance for clients.
  • Excellent analytical, problem-solving, stakeholder management, and client communication skills.
  • Professional certifications such as OSCP, OSEP, OSWE, PNPT, GPEN, CEH Practical, CRTO, or equivalent.
  • Collaborative, research-driven, and solution-oriented mindset with the ability to independently manage multiple client engagements.
  • Hybrid work flexibility.
  • Continuous learning support through certifications and professional development programs.

Responsibilities

  • Conduct end-to-end Vulnerability Assessment and Penetration Testing (VAPT) across web apps, APIs, mobile apps, networks, cloud, and enterprise infra.
  • Perform manual penetration testing to identify vulnerabilities beyond automated scans.
  • Conduct security assessments aligned with OWASP Testing Guide, PTES, NIST SP 800-115, and MITRE ATT&CK.
  • Identify and exploit vulnerabilities including OWASP Top 10, API Top 10, auth flaws, business logic issues, insecure configurations, privilege escalation.
  • Perform internal/external network testing, AD assessments, wireless security testing, and cloud security across AWS, Azure, GCP.
  • Execute Red Team assessments, adversary emulation, and attack simulations as needed.
  • Validate and prioritize vulnerabilities based on business impact, exploitability, risk.
  • Prepare detailed technical reports, executive summaries, PoC documentation, remediation guidance.
  • Support clients in remediation via re-validation testing and security consultations.
  • Mentor junior testers and improve internal methodologies, tools, and playbooks.
  • Stay updated on threats to enhance testing methods.
  • Collaborate with cross-functional teams to improve secure development practices.

Skills

Penetration Testing
Vulnerability Assessment
Offensive Security
Red Teaming
Cybersecurity Consulting
Client Engagement
Reporting
Mentoring

Tools

Burp Suite Pro
Metasploit
Nmap
Nessus
Wireshark
SQLMap
BloodHound
Impacket
Nuclei
Kali Linux

Job description

Join Tsaaro as a Senior Penetration Tester

Hack with Purpose. Strengthen Security. Build CyberResilience.

Are you passionate about offensive security, ethicalhacking, and helping organizations identify and eliminate securityvulnerabilities before attackers can exploit them?

At Tsaaro, we go beyond vulnerability identification—wehelp organizations proactively strengthen their cybersecurity posture throughcomprehensive Vulnerability Assessment and Penetration Testing (VAPT), Red Teamexercises, cloud security assessments, and offensive security consulting. Weare looking for a Senior Penetration Tester who thrives in consultingenvironments, enjoys solving complex security challenges, and can deliverpractical, risk-based security solutions to clients.

At Tsaaro, privacy and cybersecurity are at the heartofeverything we do. Our team of cybersecurity specialists and privacy consultantsworks closely with organizations to identify vulnerabilities, assess cyberrisks, strengthen security controls, and build resilient cyber defenseprograms.

Our consulting approach focuses on delivering practical,business-aligned cybersecurity solutions that help clients secure criticalassets, reduce cyber risk, achieve compliance, and stay ahead of evolvingthreats.

As a Senior Penetration Tester, you will lead and executeVulnerability Assessment and Penetration Testing (VAPT) engagements across webapplications, APIs, mobile applications, networks, cloud environments, andenterprise infrastructure. You will work closely with clients to identifyexploitable vulnerabilities, simulate real-world attack scenarios, validatesecurity controls, and provide actionable remediation recommendations tostrengthen their overall cybersecurity posture.

Key Responsibilities

  • Conductend-to-end Vulnerability Assessment and Penetration Testing (VAPT) acrossweb applications, APIs, mobile applications, internal and externalnetworks, cloud environments, and enterprise infrastructure.
  • Performmanual penetration testing to identify and validate securityvulnerabilities beyond automated vulnerability scans.
  • Conductsecurity assessments aligned with industry methodologies such as OWASPTesting Guide, PTES, NIST SP 800-115, and MITRE ATT&CK.
  • Identifyand exploit vulnerabilities including OWASP Top 10, OWASP API Security Top10, authentication and authorization flaws, business logicvulnerabilities, insecure configurations, privilege escalation, andinfrastructure weaknesses.
  • Performinternal and external network penetration testing, Active Directoryassessments, wireless security testing, and cloud security assessmentsacross AWS, Microsoft Azure, and Google Cloud Platform.
  • ExecuteRed Team assessments, adversary emulation exercises, and attacksimulations where required.
  • Validateand prioritize vulnerabilities based on business impact, exploitability,and risk.
  • Preparedetailed technical reports, executive summaries, proof-of-conceptdocumentation, and actionable remediation recommendations.
  • Supportclients in vulnerability remediation by performing re-validation testingand security consultations.
  • Mentorjunior penetration testers and contribute to the continuous improvement ofinternal methodologies, tools, automation scripts, and offensive securityplaybooks.
  • Stayupdated on emerging cyber threats, attack techniques, exploit research,and security vulnerabilities to continuously enhance testingmethodologies.
  • Collaboratewith cross-functional teams to improve secure development practices,strengthen security controls, and enhance clients' overall cybersecurityresilience.
Requirements
  • 3-6+ years of experience in Penetration Testing, Vulnerability Assessment(VAPT), Offensive Security, Red Teaming, or Cybersecurity Consulting.
  • Stronghands-on experience in web application, API, mobile application, network,cloud, and infrastructure penetration testing.
  • Deepunderstanding of OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CKFramework, PTES, NIST SP 800-115, and common penetration testingmethodologies.
  • Hands-onexperience with offensive security tools such as Burp Suite Professional,Metasploit, Nmap, Nessus, Wireshark, SQLMap, BloodHound, Impacket, Nuclei,Kali Linux, and similar tools.
  • Experienceconducting security assessments across AWS, Microsoft Azure, and GoogleCloud Platform.
  • Strongunderstanding of networking protocols, Windows and Linux security, ActiveDirectory, authentication mechanisms, and secure application architecture.
  • Experiencepreparing technical penetration testing reports, executive summaries, andremediation guidance for clients.
  • Excellentanalytical, problem-solving, stakeholder management, and clientcommunication skills.
  • Professionalcertifications such as OSCP, OSEP, OSWE, PNPT, GPEN, CEH Practical, CRTO,or equivalent offensive security certifications are highly preferred.
  • Acollaborative, research-driven, and solution-oriented mindset with theability to independently manage multiple client engagements.
  • Workwith one of India's fastest-growing privacy and cybersecurity consultingfirms.
  • Gainexposure to global clients across diverse industries.
  • Leadadvanced penetration testing and offensive security engagements.
  • Accelerateyour career with mentorship and leadership opportunities.
  • Hybridwork flexibility.
  • Continuouslearning support through certifications and professional developmentprograms.

From the Tsaaro Team

"At Tsaaro, we believe the strongest securityprograms are built by continuously challenging them. If you're passionate aboutoffensive security, uncovering hidden risks, and helping organizationsstrengthen their cyber resilience, we'd love to have you on our team."

Ready to Advance Your Cyber Security Career?

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Penetration Tester
Senior Penetration Tester

Tsaaro Consulting Inc. • Bengaluru

Hybrid
INR 2,000,000 - 3,200,000
Senior Penetration Tester
Senior Penetration Tester

Tsaaro People Consulting • Bengaluru

Hybrid
INR 1,800,000 - 3,500,000
Hybrid work flexibility
Global client exposure
Professional development
Hiring For Penetration Tester - Mumbai
Hiring For Penetration Tester - Mumbai

Saint Gobain • Mumbai, Navi Mumbai

On-site
INR 4,000,000 - 8,000,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Kroll • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Senior Penetration Tester
Senior Penetration Tester

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 2,500,000 - 4,000,000
Hybrid Working
Cyber Penetration Tester Senior
Cyber Penetration Tester Senior

Baker Tilly • Gurugram District, Bengaluru

Hybrid
INR 1,500,000 - 2,500,000
Senior Penetration Tester
Senior Penetration Tester

AppSecure Security • Bengaluru Urban

Remote
INR 1,500,000 - 2,100,000
Competitive compensation package
Comprehensive health insurance
Company-sponsored off-sites
+2
Sr. Consultant/Lead Consultant – Application Penetration Tester (APT)
Sr. Consultant/Lead Consultant – Application Penetration Tester (APT)

Talpro • Mumbai

On-site
INR 1,674,000 - 2,567,000
Principal Penetration Tester
Principal Penetration Tester

CheckRed • Pune District

On-site
INR 1,500,000 - 2,000,000
Security Consultant / Penetration Tester
Security Consultant / Penetration Tester

The Missing Link • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Collaborative environment
Professional development opportunities
Training and company paid certifications
+1