Padmi

Security Tester (Hyderabad)

HyderabadPosted 1 month ago
CybersecuritySeniorFull Time; Regular
Apply at ZEN Cloud Systems Private

Opens the source posting on shine.com

Source description

About the role

View original

About the Role: Penetration Tester Duration: 6 months Location: Hyderabad Timings: Full Time (As per company timings) Notice Period: (Immediate Joiner - Only) Experience: 5-7 Years (General Shift & UK shift), 5days work from the Office, a Cab facility is there. Job responsibilities: - Conducting and coordinating comprehensive Attack Surface Discovery, Penetration tests, and Cloud on system and network levels, employing advanced ethical hacking techniques. - Application Penetration Testing (Browser-based, API, Mobile, IoT) - Threat Modeling - Source Code Review - Perform red team exercises to determine weaknesses in the clients infrastructure and how it should be remediated. - Organizing and delivering technical security operational briefings for both technical and non-technical audiences. - Set scope, objectives, and timelines for penetration testing engagements and leverage data to create useful metrics. - Perform credentialed DAST scans on known client URLs. - Research to identify new attack vectors. - Review and provide feedback for all Security Artifacts. - Play a critical role in building an AppSec program that has a wide scope and impact. - Researching open-source emerging technologies, developing required frameworks and capabilities to perform red team exercises on new technologies adopted by clients. - Preparing and delivering clear, accurate, and concise written and oral technical reports for management. Job specifications: - Bachelors degree in Engineering or closely related coursework in technology development disciplines - Certifications like OSCP, CEH, OSCE, OSWE, GPEN, GCIH, GWAPT, or GXPN are desirable - Total Experience - 4+ years Knowledge and Experience: - Offensive Security Certified Skilled (OSCP) and/or Offensive Security Certified Expert (OSCE). - A thorough understanding of the Secure Development Life Cycle - Have familiarity with common threat tactics and tools (Nmap, Metasploit, Kali Linux, Burp Suite Pro, CobaltStrike, App D .

One address, no account. We’ll tell you when matching roles go live.