Senior Penetration Tester / Lead – Red Team
$10,000–$10,000 year
On-siteHyderabad, Telangana, India
Job Summary
Conduct advanced Vulnerability Assessment and Penetration Testing (VAPT) across external infrastructure, internal networks, web/mobile applications, APIs, and cloud environments (AWS, Azure, GCP). Execute Dynamic Application Security Testing (DAST) and Breach and Attack Simulation (BAS) scenarios to test resilience against real-world adversary tactics. Deliver customized hardening guides and compliance-aligned baselines for client-specific regulatory frameworks. Prepare comprehensive technical reports and executive summaries highlighting vulnerabilities, attack paths, and remediation guidance. Continuously research emerging attack vectors, zero-day vulnerabilities, and new CIS benchmark updates to refine assessment strategies. Contribute to Ransomware Resiliency Assessments by simulating ransomware behaviors and evaluating control effectiveness.
Required Qualifications
- 8–12 years of direct, hands-on cybersecurity consulting experience
- deep expertise in VAPT
- CIS benchmarking
- application security testing (DAST)
- Proven track record performing end-to-end penetration tests
- dynamic application security scans
- industry tools such as Burp Suite Pro
- OWASP ZAP
- Nessus
- Qualys
- Netsparker
- Acunetix
- custom scripts
- Strong understanding of web application security flaws
- OWASP Top 10
- API security issues
- authentication/authorization flaws
- injection attacks
- deserialization
- SSRF
- RCE
- ability to exploit and document them
- Solid understanding of network protocols
- operating system behaviors
- common application security principles
- modern IT environments
- Hands-on experience with CIS Benchmark implementation
- verification across diverse platforms
- alignment with client compliance mandates
- Familiarity with BAS tools
- adversary emulation frameworks
- measure detection and response maturity
- Proficiency in scripting/automation
- Python
- PowerShell
- Bash
- extend testing capabilities
- validate findings
- Working knowledge of security architecture frameworks
- SABSA
- threat modeling methodologies
- STRIDE
- kill chains
- attack trees
- support risk-informed vulnerability assessments
- hardening efforts
- remediation planning
- Ability to write and present detailed remediation reports
- security recommendations
- compliance-aligned hardening outputs
- Strong communication skills
- convey technical findings
- technical and executive stakeholders
- CEH Certification (Mandatory)
- one or more advanced certifications
- OSCP
- eCPPT
- CompTIA Pentest+
- CRTP / CRTE
- CIS-CAT Pro Assessor
- equivalent CIS Benchmark credentials
- Familiarity with MITRE ATT&CK
- adversary simulation frameworks
- Self-starter and quick learner requiring minimal ramp-up
- Excellent written, oral, and interpersonal communication skills
- Highly self-motivated, self-directed, and attentive to detail
- Ability to effectively prioritize and execute tasks in a high-pressure environment
- Location: Nopal Cyber, Hyderabad (Work from Office, 5 Days a Week)
- Employment Type: Full-time
Desired Qualifications
- Bachelor's degree in engineering, Computer Science, or related discipline
- Preferred Qualifications
- Self-starter and quick learner requiring minimal ramp-up
- Excellent written, oral, and interpersonal communication skills
- Highly self-motivated, self-directed, and attentive to detail
- Ability to effectively prioritize and execute tasks in a high-pressure environment
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.