Join Tsaaro as a Senior Penetration Tester
Hack with Purpose. Strengthen Security. Build CyberResilience.
Are you passionate about offensive security, ethicalhacking, and helping organizations identify and eliminate securityvulnerabilities before attackers can exploit them?
At Tsaaro, we go beyond vulnerability identification—wehelp organizations proactively strengthen their cybersecurity posture throughcomprehensive Vulnerability Assessment and Penetration Testing (VAPT), Red Teamexercises, cloud security assessments, and offensive security consulting. Weare looking for a Senior Penetration Tester who thrives in consultingenvironments, enjoys solving complex security challenges, and can deliverpractical, risk-based security solutions to clients.
At Tsaaro, privacy and cybersecurity are at the heartofeverything we do. Our team of cybersecurity specialists and privacy consultantsworks closely with organizations to identify vulnerabilities, assess cyberrisks, strengthen security controls, and build resilient cyber defenseprograms.
Our consulting approach focuses on delivering practical,business-aligned cybersecurity solutions that help clients secure criticalassets, reduce cyber risk, achieve compliance, and stay ahead of evolvingthreats.
As a Senior Penetration Tester, you will lead and executeVulnerability Assessment and Penetration Testing (VAPT) engagements across webapplications, APIs, mobile applications, networks, cloud environments, andenterprise infrastructure. You will work closely with clients to identifyexploitable vulnerabilities, simulate real-world attack scenarios, validatesecurity controls, and provide actionable remediation recommendations tostrengthen their overall cybersecurity posture.
Key Responsibilities
- Conductend-to-end Vulnerability Assessment and Penetration Testing (VAPT) acrossweb applications, APIs, mobile applications, internal and externalnetworks, cloud environments, and enterprise infrastructure.
- Performmanual penetration testing to identify and validate securityvulnerabilities beyond automated vulnerability scans.
- Conductsecurity assessments aligned with industry methodologies such as OWASPTesting Guide, PTES, NIST SP 800-115, and MITRE ATT&CK.
- Identifyand exploit vulnerabilities including OWASP Top 10, OWASP API Security Top10, authentication and authorization flaws, business logicvulnerabilities, insecure configurations, privilege escalation, andinfrastructure weaknesses.
- Performinternal and external network penetration testing, Active Directoryassessments, wireless security testing, and cloud security assessmentsacross AWS, Microsoft Azure, and Google Cloud Platform.
- ExecuteRed Team assessments, adversary emulation exercises, and attacksimulations where required.
- Validateand prioritize vulnerabilities based on business impact, exploitability,and risk.
- Preparedetailed technical reports, executive summaries, proof-of-conceptdocumentation, and actionable remediation recommendations.
- Supportclients in vulnerability remediation by performing re-validation testingand security consultations.
- Mentorjunior penetration testers and contribute to the continuous improvement ofinternal methodologies, tools, automation scripts, and offensive securityplaybooks.
- Stayupdated on emerging cyber threats, attack techniques, exploit research,and security vulnerabilities to continuously enhance testingmethodologies.
- Collaboratewith cross-functional teams to improve secure development practices,strengthen security controls, and enhance clients' overall cybersecurityresilience.
Requirements
- 3-6+ years of experience in Penetration Testing, Vulnerability Assessment(VAPT), Offensive Security, Red Teaming, or Cybersecurity Consulting.
- Stronghands-on experience in web application, API, mobile application, network,cloud, and infrastructure penetration testing.
- Deepunderstanding of OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CKFramework, PTES, NIST SP 800-115, and common penetration testingmethodologies.
- Hands-onexperience with offensive security tools such as Burp Suite Professional,Metasploit, Nmap, Nessus, Wireshark, SQLMap, BloodHound, Impacket, Nuclei,Kali Linux, and similar tools.
- Experienceconducting security assessments across AWS, Microsoft Azure, and GoogleCloud Platform.
- Strongunderstanding of networking protocols, Windows and Linux security, ActiveDirectory, authentication mechanisms, and secure application architecture.
- Experiencepreparing technical penetration testing reports, executive summaries, andremediation guidance for clients.
- Excellentanalytical, problem-solving, stakeholder management, and clientcommunication skills.
- Professionalcertifications such as OSCP, OSEP, OSWE, PNPT, GPEN, CEH Practical, CRTO,or equivalent offensive security certifications are highly preferred.
- Acollaborative, research-driven, and solution-oriented mindset with theability to independently manage multiple client engagements.
- Workwith one of India's fastest-growing privacy and cybersecurity consultingfirms.
- Gainexposure to global clients across diverse industries.
- Leadadvanced penetration testing and offensive security engagements.
- Accelerateyour career with mentorship and leadership opportunities.
- Hybridwork flexibility.
- Continuouslearning support through certifications and professional developmentprograms.
From the Tsaaro Team
"At Tsaaro, we believe the strongest securityprograms are built by continuously challenging them. If you're passionate aboutoffensive security, uncovering hidden risks, and helping organizationsstrengthen their cyber resilience, we'd love to have you on our team."
Ready to Advance Your Cyber Security Career?