Alignity logo
AlignityPosted 3 months ago
EXPIRED

Senior Penetration Tester

On-siteHyderabad, Telangana, India

ContractSenior LevelSmall

Job Summary

Lead technical scoping of penetration testing engagements based on business requirements, architecture reviews, and risk assessments. Perform advanced manual testing across web applications, mobile platforms, APIs, networks, and thick client apps to identify attack paths and security gaps. Conduct hands-on vulnerability validation, distinguish false positives, and provide consultative remediation guidance through verbal discussions and detailed executive reports. Manage multiple engagements while delivering actionable security recommendations aligned with business risk. Leverage scripting, automation, and AI-assisted techniques to enhance testing efficiency, including specialized validation for LLM security and prompt injection scenarios. Maintain technical proficiency through continuous research and contribute to internal methodology enhancements.

Required Qualifications

  • 5–8 years of hands-on experience in Manual Web Application Penetration Testing
  • 5–8 years of hands-on experience in Manual Mobile Application Penetration Testing
  • 5–8 years of hands-on experience in API / Web Services Security Testing
  • 5–8 years of hands-on experience in Network Penetration Testing
  • Strong expertise in identifying and exploiting common application and infrastructure vulnerabilities
  • Experience with security testing tools such as Burp Suite
  • Experience with security testing tools such as OWASP ZAP
  • Experience with security testing tools such as Metasploit
  • Experience with security testing tools such as SQLMap
  • Experience with security testing tools such as Nmap
  • Experience with security testing tools such as Postman
  • Experience with security testing tools such as Swagger
  • Experience with security testing tools such as Qualys
  • Strong experience using Kali Linux or similar penetration testing platforms
  • Good understanding of OWASP Top 10
  • Good understanding of OWASP API Security Top 10
  • Good understanding of MITRE ATT&CK Framework
  • Good understanding of Application Security Principles
  • Good understanding of Attack Methodologies
  • Working knowledge of scripting languages such as Python, Bash, or PowerShell
  • Strong analytical, troubleshooting, and communication skills
  • Ability to explain technical vulnerabilities and remediation steps to both technical and non-technical stakeholders
  • Experience working in fast-paced, multi-stakeholder, global delivery environments

Desired Qualifications

  • Exposure to OWASP LLM Top 10
  • Exposure to AI-assisted Security Testing
  • Exposure to AI-enabled Application Security Assessments
  • Exposure to Reverse Engineering Techniques
  • Exposure to Cloud Security Testing
  • Exposure to SAST / DAST tools
  • Familiarity with secure coding practices and remediation validation
  • Relevant certifications such as OSCP
  • Relevant certifications such as OSWE
  • Relevant certifications such as OSEP
  • Relevant certifications such as GPEN
  • Relevant certifications such as GWAPT
  • Relevant certifications such as GMOB
  • Relevant certifications such as eCPPT

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Find similar roles