TEST MODULE LEAD - Penetration Testing

Happiest Minds Technologies

Bengaluru

On-site

INR 1,674,000 - 2,344,000

Part time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Happiest Minds Technologies is seeking a seasoned security testing contractor in Bengaluru to conduct comprehensive penetration testing across web, mobile, APIs, and cloud-native environments. The role emphasizes AI/LLM security testing, including risk assessment for AI agents, prompts, and MCP-based apps, with hands-on PoCs and evidence-based reporting.

The contractor will design adversarial prompts, validate remediation plans, and stay updated on evolving threats and testing methodologies,

Qualifications

  • Bachelor's degree in computer science, information security, or a related discipline.
  • 4+ years of hands-on experience delivering vulnerability assessment and penetration testing engagements.
  • Strong understanding of OWASP Top 10 around Web, API, LLM, Agentic Apps & MCP, SANS Top 25, OSSTMM, PTES, and NIST standards.
  • 2+ years of strong understanding of GenAI risks, including prompt injection, sensitive data leakage, insecure output handling, hallucination, and model misuse.

Responsibilities

  • Core Penetration Testing: detailed testing of web, mobile, APIs, and networks using automated and manual methods.
  • AI/LLM Security Testing: assess AI chatbots, agents, MCP-based apps, and governance of AI risks.
  • Execute hands-on AI security test scenarios covering prompt injection, jailbreaks, data leakage, and policy bypass.
  • Design and run adversarial prompts to test model robustness.
  • Reporting & Remediation: classify vulnerabilities and deliver clear reports with evidence and PoCs.
  • Collaboration & Delivery Support: work with security, dev, and project teams to validate risks and support remediation.
  • Stay current with emerging threats and testing methodologies.

Skills

OWASP Top 10
AI security testing
Penetration testing
Strong English comms

Education

Bachelor's degree in computer science / information security
OSCP / OSWE / CEH certifications

Tools

HCL AppScan
Burp Suite

Job description

Contract Scope & Responsibilities
  • Core Penetration Testing: Conduct detailed penetration testing of web applications, mobile applications, thick clients, cloud-native applications, APIs, and network environments using both automated tools and manual testing techniques.
  • AI/LLM Security Testing: Assess AI chatbots, AI agents, and Model Context Protocol (MCP)-based applications, including risks introduced by AI systems and how those risks can be tested, governed, and reduced.
  • Execute hands‑on AI security test scenarios covering prompt injection, jailbreaks, harmful outputs, sensitive data leakage, tool misuse, hallucination, grounding failures, and policy bypass.
  • Design and run adversarial prompts to test model and guardrail robustness.
  • Reporting & Remediation: Identify, classify, and prioritize vulnerabilities based on risk and business impact, and prepare clear reports with findings, evidence, and proof‑of‑concept details where applicable.
  • Collaboration & Delivery Support: Work with internal security, development, and project teams to understand application functionality, validate risks, communicate findings, and support remediation discussions within the agreed engagement scope.
  • Stay current with emerging security threats, vulnerabilities, technologies, and testing methodologies.
  • Contribute to agreed security testing templates, reporting formats, methodologies, and process documentation where required for the engagement.
Required Contractor Profile
  • Bachelor?s degree in computer science, information security, or a related discipline.
  • 4+ years of hands‑on experience delivering vulnerability assessment and penetration testing engagements.
  • Strong understanding of OWASP Top 10 around Web, API, LLM, Agentic Apps & MCP, SANS Top 25, OSSTMM, PTES, and NIST standards.
  • 2+ years of strong understanding and hands‑on of common GenAI risks, including prompt injection, sensitive data leakage, insecure output handling, excessive agency, hallucination, and model misuse.
  • Ability to write and execute structured AI security test cases.
  • Hands‑on experience with leading application security testing tools such as HCL AppScan and Burp Suite.
  • Good conceptual understanding and practical hands‑on experience with SAST, DAST, and other security testing approaches relevant to software development.
  • Strong foundation in application architecture, development practices, and the software development lifecycle.
  • Strong knowledge of secure software development principles, including cryptography, authentication mechanisms, and security protocols.
  • Relevant certifications such as OSCP, OSWE, or CEH are a plus.
  • Strong English communication skills, both written and verbal.
Engagement Expectations
  • Strong communication and presentation skills, with the confidence to engage effectively with stakeholders.
  • Ability to work collaboratively and effectively with cross‑functional and geographically dispersed teams.
  • Availability to support agreed engagement timelines and occasional coordination across global time zones, as required.
  • Self‑driven working style with the ability to deliver quality outputs independently and within agreed timelines.
  • Ability to clearly document testing scope, assumptions, limitations, evidence, and recommendations for internal review.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Penetration Tester
Cyber Penetration Tester

Alignity Solutions • Hyderabad

On-site
INR 1,000,000 - 1,500,000
CyberSecurity
CyberSecurity

Cloudxtreme • Hyderabad, Bengaluru

On-site
INR 170,000 - 210,000
Cyber security - Penetration Testing
Cyber security - Penetration Testing

Cloudxtreme • Hyderabad, Bengaluru

Hybrid
INR 1,200,000 - 1,800,000
Cyber Security Specialist
Cyber Security Specialist

Muthoot FinCorp (MFL) • India

On-site
INR 1,200,000 - 2,400,000
Senior Security Engineer
Senior Security Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Security Tester
Security Tester

Disprz • Chennai District

On-site
INR 1,800,000 - 3,600,000
Security Tester
Security Tester

Paramount Computer Systems LLC • Coimbatore District

On-site
INR 900,000 - 1,300,000
Senior Penetration Tester
Senior Penetration Tester

Jobtailor • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000
Penetration Tester ( F2F Interviews - Mumbai )
Penetration Tester ( F2F Interviews - Mumbai )

KPMG Assurance and Consulting Services LLP • Mumbai, Navi Mumbai

On-site
INR 1,200,000 - 1,800,000