SISA Information Security - Network Security Engineer

SISA

Bengaluru

On-site

INR 2,000,000 - 3,000,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SISA in Bengaluru is seeking a senior offensive security professional with deep expertise in red team operations, adversary emulation, black-box network and cloud penetration testing, phishing simulations, C2 operations, and custom exploit development.

You will lead engagements across on-prem and cloud environments, design attack scenarios through reconnaissance to privilege escalation, deliver actionable reports, and mentor junior team members while contributing to playbooks and tooling.

Qualifications

  • 7+ years of senior offensive security experience with red team leadership.
  • Strong practical knowledge of adversary emulation and cloud pentesting.
  • Experience executing phishing simulations and initial access campaigns.

Responsibilities

  • Lead red team, adversary emulation, and both network and cloud penetration testing engagements.
  • Plan and execute attack scenarios from recon to privilege escalation and persistence.
  • Utilize C2 frameworks like Cobalt Strike, Sliver, Mythic, Havoc, Metasploit in authorized assessments.
  • Design phishing campaigns and initial access payload deliveries.
  • Develop custom exploits and proof-of-concept tooling.
  • Conduct Active Directory and hybrid identity attack simulations.
  • Penetration testing across AWS, Azure, GCP focusing on IAM and misconfigurations.
  • Prepare detailed findings, business impact, and remediation steps; present to stakeholders.
  • Mentor juniors and contribute to red team playbooks and tooling.

Skills

Red teaming
Adversary emulation
Black-box testing
Network pentesting
Cloud pentesting
Phishing simulations
Exploit development
Active Directory attacks
Python scripting
PowerShell scripting
Bash scripting
Go/C/C++
OPSEC & evasion
MITRE ATT&CK mapping
Reporting & communication

Tools

BloodHound
Mimikatz
Impacket
CrackMapExec
Responder
Evilginx
GoPhish
Nmap
Masscan
Nessus
Burp Suite
Wireshark
Hashcat
Pacu
Prowler
ScoutSuite
AzureHound
ROADtools

Job description

We are looking for a senior offensive security professional with strong expertise in red team operations, adversary emulation, black-box network penetration testing, cloud penetration testing, phishing simulations, C2 operations, and custom exploit development.

Experience

7 - 10 years.

Location

Bangalore.

Employment Type

Full-time.

Key Responsibilities
  • Lead red team, adversary emulation, black-box network, cloud, and infrastructure penetration testing engagements.
  • Plan and execute attack scenarios covering reconnaissance, initial access, exploitation, privilege escalation, lateral movement, persistence, and objective-based actions.
  • Use adversary emulation platforms and C2 frameworks such as Cobalt Strike, Sliver, Mythic, Havoc, Metasploit, and similar tools in authorized assessments.
  • Design and execute phishing simulation campaigns, payload delivery scenarios, and initial access simulations.
  • Perform custom exploit development, exploit modification, payload customization, and proof-of-concept development for identified vulnerabilities.
  • Conduct Active Directory and hybrid identity attack simulations, including credential attacks, lateral movement, privilege escalation, and domain compromise scenarios.
  • Perform cloud penetration testing across AWS, Azure, and GCP, focusing on IAM abuse, exposed assets, storage misconfigurations, insecure networking, excessive permissions, and privilege escalation paths.
  • Assess endpoint, network, identity, cloud, and email security controls from an attackers perspective.
  • Support purple team and detection validation exercises by mapping techniques to MITRE ATT&CK.
  • Prepare detailed reports covering attack chains, exploited weaknesses, business impact, evidence, and remediation recommendations.
  • Present findings and attack narratives to technical teams, leadership, and client stakeholders.
  • Mentor junior team members and contribute to red team playbooks, tooling, labs, and methodologies.
Required Skills
  • Strong hands-on expertise in red teaming, adversary emulation, black-box testing, network penetration testing, and cloud pentesting.
  • Practical experience with C2 and adversary emulation platforms such as Cobalt Strike, Sliver, Mythic, Havoc, Metasploit, Covenant, or similar frameworks.
  • Experience in phishing simulations, payload delivery, social engineering assessments, and initial access simulation.
  • Ability to perform custom exploit development, exploit chaining, payload customization, and proof-of-concept creation.
  • Strong knowledge of Active Directory attack techniques, including Kerberoasting, AS-REP roasting, NTLM relay, pass-the-hash, pass-the-ticket, delegation abuse, ACL abuse, and domain escalation paths.
  • Good understanding of cloud attack techniques across AWS, Azure, and GCP, including IAM abuse, storage exposure, metadata service abuse, key leakage, role assumption, and privilege escalation.
  • Experience with tools such as BloodHound, Mimikatz, Impacket, NetExec/CrackMapExec, Responder, Evilginx, GoPhish, Nmap, Masscan, Nessus, Burp Suite, Wireshark, Hashcat, Hydra, Pacu, Prowler, ScoutSuite, AzureHound, ROADtools etc.
  • Scripting and automation skills in Python, PowerShell, Bash, Go, or C/C++.
  • Good understanding of OPSEC, payload handling, evasion concepts, attack path mapping, and detection-aware testing.
  • Strong reporting, stakeholder communication, and client-facing skills.
Good To Have
  • Experience with EDR/AV evasion testing in authorized environments.
  • Experience with malware analysis, reverse engineering, or implant customization.
  • Exposure to Kubernetes, Docker, and container security assessments.
  • Experience conducting purple team exercises and detection engineering support.
  • Certifications such as OSCP, OSEP, GPEN, GXPN, PNPT, eCPPT or CEH.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hiring For Penetration Tester - Mumbai
Hiring For Penetration Tester - Mumbai

Saint Gobain • Mumbai, Navi Mumbai

On-site
INR 4,000,000 - 8,000,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Jobtailor • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Red Team Specialist
Red Team Specialist

ESP Engineered • Mumbai

On-site
INR 1,200,000 - 2,000,000
Cutting-edge Red Team engagements
Collaborative environment
Continuous learning opportunities
Senior Manager - Information Security And Governance
Senior Manager - Information Security And Governance

HDB Financial Services Ltd. • Mumbai

On-site
INR 800,000 - 1,400,000
Cybersecurity Lead
Cybersecurity Lead

Trigyn Technologies Limited. • Gurugram District

On-site
INR 4,000,000 - 7,000,000
Senior [Red Team] Security Consultant
Senior [Red Team] Security Consultant

ILLUME Intelligence India Pvt. Ltd. • Karnataka

On-site
INR 1,800,000 - 3,000,000
Senior Penetration Tester
Senior Penetration Tester

Basebiz • Dadri

On-site
INR 1,200,000 - 2,400,000
Sr. SOC Analyst
Sr. SOC Analyst

Ferfier Technologies • Dadri

Hybrid
INR 1,500,000 - 2,100,000
Flexible/Remote work
Executive - Cyber Defense
Executive - Cyber Defense

BSR & Co • Mumbai

On-site
INR 1,400,000 - 2,300,000
Offensive Security Engineer
Offensive Security Engineer

Systems Plus • Pune District

On-site
INR 1,800,000 - 2,800,000