Specialist, Penetration Testing

Terrabit Consulting Pvt. Ltd - India

Bengaluru

On-site

INR 1,200,000 - 2,200,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Terrabit Consulting Pvt. Ltd – India seeks a Specialist in Penetration Testing to plan and execute intelligence-led security testing engagements to certify Audax platform builds and strengthen the organization's security posture.

You will design offensive security tooling, assess vulnerabilities across applications, networks, cloud, and mobile, and translate findings into risk-rated guidance for engineering and risk stakeholders.

Qualifications

  • Hands-on experience in penetration testing and vulnerability management in a global environment.
  • Lead penetration tester, reverse engineer, researcher, or threat analyst for 3+ years.
  • Familiar with TTPs used for reconnaissance, persistence, lateral movement, and exfiltration.

Responsibilities

  • Plan and execute penetration testing engagements across applications, networks, cloud, and mobile platforms.
  • Design and build custom scripts, tools, and attack frameworks.
  • Investigate vulnerabilities and produce risk-rated findings with remediation recommendations.
  • Prioritize remediation with Engineering, Infrastructure, and Product stakeholders.

Skills

Penetration testing
Vulnerability management
Reverse engineering
Threat analysis
Python
PowerShell

Tools

Python
PowerShell
Shell scripting

Job description

As a Specialist in Penetration Testing, you will plan and execute intelligence-led security testing engagements to certify Audax platform builds and strengthen the organization's security posture. Working within the Risk & Delivery function, you will design and operate offensive security tooling and methodologies that emulate real-world adversary behaviour, identify exploitable weaknesses across applications, infrastructure, and mobile platforms, and translate technical findings into clear, risk-rated guidance for engineering and risk stakeholders

Responsibilities
  • Plan and execute penetration testing engagements across applications, networks, cloud, and mobile platforms, applying a structured testing methodology to certify security control effectiveness for Audax platform builds.
  • Design and build custom scripts, tools, and attack frameworks to emulate adversary tactics, techniques, and procedures (TTPs) across the attack lifecycle, including detection-evasion approaches.
  • Investigate identified vulnerabilities and threats, assess exploitability and business impact, and produce clear, risk rated findings with corrective action recommendations.
  • Prioritize remediation with Engineering, Infrastructure, and Product stakeholders and track findings through to closure, validating remediation effectiveness.
  • Advise stakeholders on risk exposure, likely attack paths, and containment measures to support risk-informed decisions on vulnerabilities the organization could face.
  • Reverse engineer and assess iOS and Android application binaries to identify exploitation paths, including evasion of root/jailbreak detection controls.
  • Maintain and refine testing tooling, playbooks, and internal frameworks based on engagement outcomes and emerging threat intelligence.
  • Contribute to continuous improvement of penetration testing processes and tooling, including integration with DevSecOps and CI/CD practices.
  • Assess cloud and containerised environments (including AWS and Kubernetes) against security best practice as part of engagement scope.
  • Produce clear technical and management reporting summarizing test results, risk exposure, and remediation guidance for relevant stakeholders.
Qualifications
  • 69 years of hands-on experience in penetration testing and vulnerability management in a global environment, including 3+ years as a lead penetration tester, reverse engineer, researcher, or threat analyst.
  • Demonstrated experience testing web applications, mobile applications, and operating systems using techniques including injection, privilege escalation, buffer overflows, fuzzing, and scanning.
  • Working knowledge of tactics, techniques, and procedures (TTPs) used for reconnaissance, persistence, lateral movement, and exfiltration, and of the broader threat and vulnerability landscape, including malware and emerging attack methods.
  • Proficiency in one or more offensive-security-relevant languages, such as Python, PowerShell, or shell scripting, alongside familiarity with Objective-C, Java, Swift, or Assembly for mobile/OS-level work.
  • Internal
  • iOS and Android reverse engineering, disassembly, decompilation, and evasion of root/jailbreak detection.
  • Internal Ability to write and demonstrate proof-of-concept work from an exploitation/attack perspective, including building and deploying custom modules and tailored payloads for established testing frameworks.
  • Solid understanding of networking topologies, protocols, and enterprise infrastructure (switches, routers, firewalls) and their security implications.
  • Familiarity with access control methodologies, intrusion detection, vulnerability and patch management tooling, and endpoint security solutions.
  • Experience in cloud security (particularly AWS), container and Kubernetes testing, and DevSecOps/CI-CD practices.
  • Ability to communicate technical risk clearly to both technical and non-technical stakeholders, including influencing remediation decisions. .
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Penetration Tester
Senior Penetration Tester

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 2,500,000 - 4,000,000
Hybrid Working
Penetration Tester
Penetration Tester

Michael Page • Hyderabad

Hybrid
INR 2,500,000 - 5,500,000
Application Penetration Tester
Application Penetration Tester

Cortex Consultants LLC • Chennai District

On-site
INR 500,000 - 700,000
Application Security Consultant
Application Security Consultant

SecurityBoat Cybersecurity Solutions Private Limited • Mumbai

On-site
INR 1,200,000 - 2,200,000
Competitive compensation
Specialized cybersecurity team
Professional development
Mobile Application Penetration Tester ( Pentest )
Mobile Application Penetration Tester ( Pentest )

Shashwath Solution • Dadri

On-site
INR 4,500,000 - 6,500,000
Mobile Application Penetration Tester ( Pentest )
Mobile Application Penetration Tester ( Pentest )

Shashwath Solution • Pune District

On-site
INR 350,000 - 550,000
Cyber Security Specialist
Cyber Security Specialist

Muthoot FinCorp (MFL) • India

On-site
INR 1,200,000 - 2,400,000
Cyber Penetration Tester
Cyber Penetration Tester

Alignity Solutions • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Penetration Tester ME
Penetration Tester ME

BreachLock, Inc. • Dadri

On-site
INR 900,000 - 1,500,000
Private Health Insurance
Security Penetration Testing Consultant
Security Penetration Testing Consultant

Withum • Bengaluru

On-site
INR 900,000 - 1,300,000