Padmi

Security Pen Tester

BangalorePosted 1 month ago
CybersecurityMid-levelFull Time; Regular
Apply at Jobtailor

Opens the source posting on shine.com

Source description

About the role

View original

Responsibilities Conduct in-depth penetration tests on web applications, APIs, microservices, and internal SaaS components Perform manual vulnerability discovery and exploitation following OWASP methodologies Simulate adversarial attack scenarios and participate in RED Team exercises Conduct cloud-focused penetration tests and configuration reviews (AWS, OCI and Azure) Test LLM/AI features for prompt injection, jailbreaking, data leakage, model manipulation, and other emerging threats Develop custom proof-of-concept exploits where applicable Work closely with engineering and product teams to provide clear remediation guidance Use and customize security testing tools (Burp Suite, ZAP, Nmap, SQLMap, etc.) Develop scripts or small tools for automation or exploitation (Python, Bash, PowerShell, etc.) Effectively use AI tools (Microsoft Copilot, Claude, etc.) to accelerate testing, generate payloads, summarize findings, and produce documentation Create clear, detailed technical reports with reproduction steps and exploit evidence Present findings to technical and leadership teams Requirements 4+ years of handson experience in cybersecurity, with a focus on penetration testing Strong understanding of OWASP Top 10 and practical experience exploiting them in realworld applications Experience testing REST and GraphQL APIs Solid understanding of web technologies (HTML, JavaScript, SQL, authentication mechanisms, etc.) Proven experience performing manual exploitation (not just toolbased scanning) Experience testing cloudhosted applications and infrastructure (AWS, OCI and Azure) Knowledge of modern authentication (OAuth, JWT, SSO, SAML) (Preferred, Not Mandatory) Experience testing AI/LLMpowered features Knowledge of prompt injection, jailbreaks, RAG attacks, model extraction, data leakage vectors Responsibilities Conduct in-depth penetration tests on web applications, APIs, microservices, and internal SaaS components Perform manual vulnerability discovery and exploitation following OWASP methodologies Simulate adversarial attack scenarios and participate in RED Team exercises Conduct cloud-focused penetration tests and configuration reviews (AWS, OCI and Azure) Test LLM/AI features for prompt injection, jailbreaking, data leakage, model manipulation, and other emerging threats Develop custom proof-of-concept exploits where applicable Work closely with engineering and product teams to provide clear remediation guidance Use and customize security testing tools (Burp Suite, ZAP, Nmap, SQLMap, etc.) Develop scripts or small tools for automation or exploitation (Python, Bash, PowerShell, etc.) Effectively use AI tools (Microsoft Copilot, Claude, etc.) to accelerate testing, generate payloads, summarize findings, and produce documentation Create clear, detailed technical reports with reproduction steps and exploit evidence Present findings to technical and leadership teams Requirements 4+ years of handson experience in cybersecurity, with a focus on penetration testing Strong understanding of OWASP Top 10 and practical experience exploiting them in realworld applications Experience testing REST and GraphQL APIs Solid understanding of web technologies (HTML, JavaScript, SQL, authentication mechanisms, etc.) Proven experience performing manual exploitation (not just toolbased scanning) Experience testing cloudhosted applications and infrastructure (AWS, OCI and Azure) Knowledge of modern authentication (OAuth, JWT, SSO, SAML) (Preferred, Not Mandatory) Experience testing AI/LLMpowered features Knowledge of prompt injection, jailbreaks, RAG attacks, model extraction, data leakage vectors

One address, no account. We’ll tell you when matching roles go live.

More at Jobtailor

Related open roles

View all roles