Sonata Software, with over $1.2 Billion Revenue, is a leading AI-first Modernization Engineering company, powered by our unique PlatformationTM framework. Our 6400+ AI Engineers are helping enterprises transform from systems to intelligent business platforms leveraging partner ecosystem to drive speed, efficiency and growth. Our bouquet of Modernization Engineering Services with AI -first approach cuts across Cloud, Data, AI, Dynamics, Test Automation, and Managed Services.
Sonata’s AI-led modernization is enabled by a powerful suite of proprietary tools and assets. At the core is the Harmoni.AI Enterprise Platform, which includes Agent Bridge-a governance and observability framework; Agent Builder-a development toolkit for fungible agents integrated into enterprise systems; and the Agent Marketplace-an internal ecosystem for modular, reusable agents.
Headquartered in Bengaluru, India, Sonata Software has a strong global presence, including key regions US, UK, India, Malaysia, Mexico, Australia, DACH (Germany/Switzerland) & Nordics (Finland). We are a trusted partner of Fortune 500 companies in Banking, Financial Services and Insurance; Healthcare and Lifesciences; Telecom, Media, and Technology; and Retail, Manufacturing and Distribution space.
Job Title :InfrastructurePenetration tester
Experience: 8+ years
Job type :Contract
Location :San Jose CA(Onsitefrom Day 1)
Level: Senior Security Engineer / Senior Penetration Tester
Function: Cybersecurity / Offensive Security
About the Role
We are seeking anexperienced Senior Infrastructure Penetration Tester to join our OffensiveSecurity organization. The ideal candidate will have approximately 6+ years ofhands-on penetration testing experience in large-scale technology environmentsand a strong understanding of enterprise infrastructure, cloud platforms,identity systems, networks, and modern attack techniques.
In this role, you willconduct sophisticated security assessments across corporate infrastructure,cloud environments, data centers, production services, identity platforms, andinternet-facing assets. You will work closely with infrastructure, cloud, engineering,security operations, and incident response teams to identify exploitableweaknesses and drive measurable risk reduction.
The successful candidateshould be comfortable operating independently, developing attack paths,chaining vulnerabilities, and communicating technical findings to bothengineers and senior leadership.
Key Responsibilities
- Planand execute internal and external infrastructure penetration tests acrosslarge enterprise environments.
- AssessWindows, Linux, Unix, network, virtualization, container, and hybridinfrastructure.
- Conductnetwork, host, service, and application-layer security testing.
- Identifyvulnerabilities and demonstrate realistic attack paths and businessimpact.
- Performauthenticated and unauthenticated penetration testing.
- Conductlateral movement, privilege escalation, credential-access, and persistenceassessments within authorized environments.
- Evaluatesegmentation and security controls between corporate, production, R&D,cloud, and restricted environments.
- Assesssecurity of common enterprise services including DNS, DHCP, VPN, SSH,HTTP/S, LDAP, Kerberos, SMB, RDP, databases, proxies, and authenticationinfrastructure.
Active Directory & IdentitySecurity
- Performpenetration testing of Active Directory and enterprise identityenvironments.
- AssessKerberos, NTLM, LDAP, Group Policy, trusts, privileged accounts, serviceaccounts, and delegation configurations.
- Identifypaths to domain administrator and other high-value privileges.
- Evaluateidentity federation, SSO, MFA, privileged access management, and serviceidentities.
- Assessidentity attack paths across hybrid environments such as on-premisesActive Directory and cloud identity providers.
- Conductpenetration testing across AWS, Azure, and/or GCP environments.
- Assesscloud IAM, roles, policies, storage, compute, networking, APIs, secrets,and management interfaces.
- Testcloud-to-corporate and cloud-to-production attack paths.
- AssessKubernetes, containers, Docker, service meshes, and cloud-nativeinfrastructure.
- Identifyprivilege-escalation and lateral-movement opportunities across cloudenvironments.
- Evaluateinfrastructure-as-code and configuration risks where applicable.
External Attack Surface
- Performcontinuous and point-in-time assessments of internet-facinginfrastructure.
- Identifyexposed services, misconfigurations, vulnerabilities, weak authentication,and attack paths.
- Conductreconnaissance and attack-surface analysis using both commercial andopen-source technologies.
- Validatefindings from vulnerability scanners through manual exploitation andcontrolled testing.
- Assessperimeter security, WAFs, firewalls, VPNs, reverse proxies, CDNinfrastructure, and other defensive controls.
Adversary Simulation
- Developrealistic attack scenarios based on current threat actor techniques.
- Chainmultiple weaknesses to demonstrate realistic compromise scenarios.
- Collaboratewith Red Team, Purple Team, Detection Engineering, and Security Operationsteams.
- Developproof-of-concept exploits and attack automation where appropriate.
- Validatepreventive and detective security controls.
Automation & Tool Development
- Producehigh-quality penetration-testing reports that clearly communicate:
- Vulnerability
- Attackpath
- Exploitability
- Businessimpact
- Affectedassets
- Evidence
- Remediationrecommendations
- Presentfindings to engineering teams, security leadership, and executivestakeholders.
- Workwith infrastructure owners to validate remediation and perform retesting.
- Trackrecurring weaknesses and identify systemic security issues.
- Helpestablish security metrics such as remediation rates, exploitability,attack-path reduction, and risk exposure.
Required Qualifications
- 6+years of professional experience in penetration testing, offensivesecurity, infrastructure security, or closely related cybersecuritydisciplines.
- Stronghands-on experience conducting enterprise infrastructure penetrationtests.
- Deepunderstanding of TCP/IP networking and common enterprise protocols.
- StrongWindows and Linux security knowledge.
- Demonstratedexperience with Active Directory and enterprise identity systems.
- Experiencewith cloud security and at least one major cloud platform: AWS, Azure, orGCP.
- Experienceidentifying and exploiting common infrastructure vulnerabilities.
- Strongunderstanding of authentication, authorization, privilege escalation,lateral movement, and defense evasion concepts.
- Experiencewith vulnerability scanners and manual validation.
- Strongscripting skills in Python, PowerShell, Bash, or similar languages.
- Abilityto independently scope, execute, document, and communicatepenetration-testing engagements.
- Strongwritten and verbal communication skills.
- Abilityto work effectively with infrastructure and engineering teams in a largetechnology organization.
- Demonstratedability to operate within strict rules of engagement andresponsible-disclosure requirements.
Preferred Qualifications
- Experienceworking in a large-scale Big Tech or hyperscale technology environment.
- Experiencewith Kubernetes, Docker, containers, service meshes, and cloud-nativearchitectures.
- Experiencetesting CI/CD infrastructure, DevOps platforms, andinfrastructure-as-code.
- Experiencewith security testing of APIs and microservices.
- Experiencewith red teaming or adversary simulation.
- Experiencedeveloping custom offensive-security tooling.
- Experiencewith attack-path analysis and identity-centric security assessments.
- Experienceassessing zero-trust architectures.
- Experiencewith security testing of SaaS and internally developed enterpriseplatforms.
- Understandingof software supply-chain security and CI/CD attack paths.
- Experienceworking with bug bounty or vulnerability disclosure programs.
- Experienceintegrating penetration testing into enterprise security programs.
Technical Skills
Operating Systems
- Windows/ Windows Server
- macOS
Networking
- TCP/IP
- DNS
- HTTP/S
- SSH
- VPN
- SMB
- RDP
- LDAP
- TLS
- Firewalls/ WAF / Proxies
Identity
- ActiveDirectory
- LDAP
- SAML
- OAuth/OIDC
- MFA
- PAM
Cloud
- AWS
- GCP
- IAM
- VPC/VNet
- Cloudstorage
- Containers
Security Tools
Candidates should be able to understand and adapt toolsrather than simply execute automated scanners.
Core Competencies
- OffensiveSecurity Mindset
- EnterpriseInfrastructure Expertise
- Identity& Active Directory Security
- CloudSecurity
- AdversarySimulation
- Automation& Tool Development
- Risk-BasedThinking
- StrongTechnical Communication
Why join Sonata Software?
At Sonata, you´ll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what´s possible. To build never seen before solutions to some of the world’s toughest problems. You´ll be challenged, but you will not be alone. You´ll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.
Sonata Software is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity, age, religion, disability, sexual orientation, veteran status, marital status, or any other characteristics protected by law.