SISA Information Security - Senior Consultant - Penetration Testing

SISA

Bengaluru

On-site

INR 1,200,000 - 2,400,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SISA in Bengaluru requires a security tester to perform comprehensive penetration testing across web, mobile, and API platforms, plus secure code reviews. The role demands strong OWASP/SANS/NIST knowledge and hands-on tooling expertise.

You will work with developers and product teams to remediate issues and perform retests, with clear client communication throughout. OSCP or equivalent certification is mandatory, and BE/B.Tech or M.Tech in CS or Info Science is preferred.

Qualifications

  • Experience performing web, mobile, API and thick-client pen tests.
  • Proficient in automated and manual code reviews and risk assessment.
  • Strong knowledge of OWASP Top 10, SANS Top 25, and NIST standards.
  • Ability to explain findings to non-technical stakeholders.
  • Experience with remediation guidance and retesting.
  • Good written and spoken English communication.

Responsibilities

  • Conduct penetration testing on web, mobile, API and thick-client apps to identify weaknesses.
  • Perform automated and manual secure code reviews.
  • Identify and exploit vulnerabilities per OWASP Top 10, SANS Top 25, and business logic flaws.
  • Interact with clients on project updates and status.
  • Collaborate with developers and product teams for remediation support.
  • Retest after fixes are applied and verify closures.
  • Coordinate with stakeholders on remediation of open vulnerabilities.

Skills

Penetration Testing
Secure code review
Vulnerability assessment
Client communication
Remediation collaboration
Retesting
Stakeholder follow-up
OWASP Top 10
SANS Top 25
NIST standards
Reporting
Programming: PHP/HTML/JavaScript
Bug bounty mindset

Education

BE/B.Tech in CS/Information Science
M.Tech in CS/Information Science
CEH
CompTIA Security+
PenTest+
GPEN
OSCP
CREST CRT

Tools

Burp Suite
OWASP ZAP
Postman
Nmap
SQLMap
Metasploit
Echo Mirage
MobSF
Frida

Job description

  • Conduct penetration testing on web, mobile (android + ios), API, and thick-client applications to identify security weaknesses.
  • Conduct automated and manual Secure code review.
  • Identify and exploit vulnerabilities such as OWASP Top 10, SANS Top 25, and business logic flaws.
  • Client interaction on project updation/status.
  • Collaborate with developers, product teams for Remediation support.
  • Perform retest post confirmation on the fixes.
  • Follow-up with the relevant stakeholders on the remediation of open vulnerabilities.
Mandatory Certification

OSCP.

Roles And Responsibilities
  • Conduct penetration testing on web, mobile (android + ios), API, and thick-client applications to identify security weaknesses.
  • Conduct automated and manual Secure code review.
  • Identify and exploit vulnerabilities such as OWASP Top 10, SANS Top 25, and business logic flaws.
  • Client interaction on project updation/status.
  • Collaborate with developers, product teams for Remediation support.
  • Perform retest post confirmation on the fixes.
  • Follow-up with the relevant stakeholders on the remediation of open vulnerabilities.
Mandatory Skills Required For The Role
  • Web, API and Mobile Penetration Testing.
  • Proficiency With Penetration Testing Tools Such As: Burp Suite, OWASP ZAP, Postman, Nmap, SQLMap, Metasploit, Echo mirage.
  • Mobile testing tools (e.g., MobSF, Frida) is a plus.
  • Good understanding on OWASP Top 10, SANS CWE Top 25, NIST standards.
  • Good written and spoken communication skills.
  • Ability to do report walkthrough with relevant stakeholder.
  • Understanding of programming languages such as PHP, HTML, javascript, etc.
Education Requirements
  • BE/B.Tech in Computer Science or Information Science Or M.Tech in Computer Science or Information CEH, CompTIA, PenTest+, GPEN, OSCP, CREST CRT preferable.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Consultant
Senior Consultant

SISA • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Application Security Professional
Application Security Professional

Sisa Information Security • Bengaluru

On-site
INR 900,000 - 1,500,000
Application Security
Application Security

Sisainfosec • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Application Penetration Tester
Application Penetration Tester

Cortex Consultants LLC • Chennai District

On-site
INR 500,000 - 700,000
Senior Security Testing Engineer
Senior Security Testing Engineer

Allied Boston Consultants India • Dadri

On-site
INR 900,000 - 1,300,000
Software Engineer
Software Engineer

Cloudxtreme • Bengaluru, Hyderabad

Hybrid
INR 900,000 - 1,500,000
Senior Penetration Tester
Senior Penetration Tester

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 2,500,000 - 4,000,000
Hybrid Working
Sr. Security Consultant
Sr. Security Consultant

Eventussecurity • Navi Mumbai

On-site
INR 600,000 - 1,000,000
Vulnerability Assessment & Penetration Testing (VAPT) Engineer
Vulnerability Assessment & Penetration Testing (VAPT) Engineer

Zensar • Pune District

On-site
INR 1,200,000 - 2,800,000
Penetration Tester Architect ( VAPT, Android , IOS ) - Naukri.com
Penetration Tester Architect ( VAPT, Android , IOS ) - Naukri.com

Info Edge • Greater Noida, Dadri

On-site
INR 900,000 - 1,200,000