Padmi

Freelance Part-time Penetration Tester

BangalorePosted 9 months ago
CybersecurityMid-level
Apply at Han Digital Solution

Opens the source posting on naukri.com

Source description

About the role

View original

Job Title Freelance / Part-time Penetration Tester About the role We are looking for a pragmatic, detail-oriented Penetration Tester to join on a freelance/part-time basis You will carry out hands-on security assessments across applications, APIs, mobile apps, cloud and network infrastructure, identify and classify vulnerabilities, produce clear, actionable reports (with CVSS/CWE classification), and work with engineering teams to validate remediation Key responsibilities Perform penetration tests across web applications, REST/GraphQL APIs, mobile apps, cloud environments, containers, and network infrastructure Use a mix of manual testing and automated scanning to find vulnerabilities and misconfigurations Simulate realistic attack scenarios to validate exploitability and potential business impact Produce high-quality deliverables: executive summaries, technical findings, reproduction steps, remediation guidance, and retest verification Prioritize findings by severity, impact and exploitability to support remediation planning Stay current with new exploits, attack techniques, and security tools; propose improvements to testing methodology Participate in follow-up discussions with internal teams to clarify findings and advise on mitigations Comply with rules of engagement and sign NDAs as required Required skills & experience Proven hands-on experience performing penetration tests and code reviews (manual + automated) Strong knowledge of OWASP Top 10, SANS/CWE and common secure-coding pitfalls Hands-on with tools such as Burp Suite, Nmap, Metasploit, ZAP, Wireshark, Nessus, Nikto, and Kali toolset (or equivalents) Familiarity with common attack vectors: SQLi, XSS, CSRF, SSRF, RCE, IDOR, auth/privilege escalation, etc Ability to classify vulnerabilities using CWE and estimate severity (CVSS) Excellent technical writing: clear, structured reports and remediation guidance Strong communication skills and ability to engage with engineering teams Preferred / nice-to-have Certifications: OSCP, GPEN, OSWE, GWAPT, CEH (or equivalent practical experience) Experience with cloud security (AWS/Azure/GCP), container security (Docker, Kubernetes) Experience testing mobile (iOS/Android) and modern auth (OAuth2/OIDC) Prior freelance/consulting experience and sample reports or redacted findings you can share

One address, no account. We’ll tell you when matching roles go live.

More at Han Digital Solution

Related open roles

View all roles