Get more replies from employers
Send a job-specific resume in minutes.
Uplers is looking for an experienced Offensive Security Engineer in Bengaluru to perform full-scope pentesting of web, mobile apps, APIs, and cloud environments. You will exploit vulnerabilities, assess risk, and deliver actionable remediation plans to development teams.
The role requires 2+ years of professional offensive security experience, deep OWASP Top 10 knowledge, AD attack paths, and tools like Burp Suite Pro, Metasploit, Nmap, and Cobalt Strike.
Experience: 2.00 + years
Salary: INR 700000-1200000 / year (based on experience)
Expected Notice Period: 30 Days
Shift: (GMT+05:30) Asia/Kolkata (IST)
Opportunity Type: Office ()
Placement Type: Full Time Permanent position(Payroll and Compliance to be managed by: Computer and Network Security)
(*Note: This is a requirement for one of Uplers' client - Computer and Network Security)
Must have skills required: and bug bounty experience., CI/CD security, Cloud exploitation, custom exploit development, Kubernetes security, OSCP/OSWE/OSEP/CRTO certifications, red teaming, Reverse Engineering, Threat hunting, AWS/Azure security, Burp Suite Pro, Manual & automated penetration testing, OWASP Top 10, Python/Go/Bash scripting, Web/Mobile/API security testing
Full-Scope Pentesting: Conduct manual and automated penetration tests on web/mobile apps, APIs, AI agents testing, networks, and cloud environments (AWS/Azure).
Exploitation & Risk Analysis: Manually exploit vulnerabilities to demonstrate real-world impact, moving beyond simple automated scanning.
Reporting & Remediation: Write clear, actionable technical reports and collaborate directly with developers to guide fix implementations.
Tooling: Develop and maintain custom scripts (Python, Go, or Bash) to automate testing workflows and bypass modern defenses.
Experience: 2+ years of dedicated professional experience in offensive security / ethical hacking.
Tech Stack: Deep knowledge of the OWASP Top 10, Active Directory attack paths, and industry tools (Burp Suite Pro, Metasploit, Nmap, Cobalt Strike).
Certifications: OSCP is preferred. (Equivalent certifications like OSWE, OSEP, or CRTO are a major plus).
Communication: Strong technical writing skills with the ability to translate complex flaws into business risk for non-technical stakeholders.