Nopal Cyber logo
Nopal CyberPosted 5 months ago

Senior Penetration Tester / Lead – Red Team

$10,000–$10,000 year

On-siteHyderabad, Telangana, India

Full TimeSenior LevelSmall

Job Summary

Conduct advanced Vulnerability Assessment and Penetration Testing (VAPT) across external infrastructure, internal networks, web/mobile applications, APIs, and cloud environments (AWS, Azure, GCP). Execute Dynamic Application Security Testing (DAST) and Breach and Attack Simulation (BAS) scenarios to test resilience against real-world adversary tactics. Deliver customized hardening guides and compliance-aligned baselines for client-specific regulatory frameworks. Prepare comprehensive technical reports and executive summaries highlighting vulnerabilities, attack paths, and remediation guidance. Continuously research emerging attack vectors, zero-day vulnerabilities, and new CIS benchmark updates to refine assessment strategies. Contribute to Ransomware Resiliency Assessments by simulating ransomware behaviors and evaluating control effectiveness.

Required Qualifications

  • 8–12 years of direct, hands-on cybersecurity consulting experience
  • deep expertise in VAPT
  • CIS benchmarking
  • application security testing (DAST)
  • Proven track record performing end-to-end penetration tests
  • dynamic application security scans
  • industry tools such as Burp Suite Pro
  • OWASP ZAP
  • Nessus
  • Qualys
  • Netsparker
  • Acunetix
  • custom scripts
  • Strong understanding of web application security flaws
  • OWASP Top 10
  • API security issues
  • authentication/authorization flaws
  • injection attacks
  • deserialization
  • SSRF
  • RCE
  • ability to exploit and document them
  • Solid understanding of network protocols
  • operating system behaviors
  • common application security principles
  • modern IT environments
  • Hands-on experience with CIS Benchmark implementation
  • verification across diverse platforms
  • alignment with client compliance mandates
  • Familiarity with BAS tools
  • adversary emulation frameworks
  • measure detection and response maturity
  • Proficiency in scripting/automation
  • Python
  • PowerShell
  • Bash
  • extend testing capabilities
  • validate findings
  • Working knowledge of security architecture frameworks
  • SABSA
  • threat modeling methodologies
  • STRIDE
  • kill chains
  • attack trees
  • support risk-informed vulnerability assessments
  • hardening efforts
  • remediation planning
  • Ability to write and present detailed remediation reports
  • security recommendations
  • compliance-aligned hardening outputs
  • Strong communication skills
  • convey technical findings
  • technical and executive stakeholders
  • CEH Certification (Mandatory)
  • one or more advanced certifications
  • OSCP
  • eCPPT
  • CompTIA Pentest+
  • CRTP / CRTE
  • CIS-CAT Pro Assessor
  • equivalent CIS Benchmark credentials
  • Familiarity with MITRE ATT&CK
  • adversary simulation frameworks
  • Self-starter and quick learner requiring minimal ramp-up
  • Excellent written, oral, and interpersonal communication skills
  • Highly self-motivated, self-directed, and attentive to detail
  • Ability to effectively prioritize and execute tasks in a high-pressure environment
  • Location: Nopal Cyber, Hyderabad (Work from Office, 5 Days a Week)
  • Employment Type: Full-time

Desired Qualifications

  • Bachelor's degree in engineering, Computer Science, or related discipline
  • Preferred Qualifications
  • Self-starter and quick learner requiring minimal ramp-up
  • Excellent written, oral, and interpersonal communication skills
  • Highly self-motivated, self-directed, and attentive to detail
  • Ability to effectively prioritize and execute tasks in a high-pressure environment

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce