{"id":1223379,"url":"https://alion.io/job/3i-infotech-penetration-tester","title":"Penetration tester","company":{"id":180701,"name":"3i Infotech","domain":"3i-infotech.com","url":"https://alion.io/company/3i-infotech","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Career site","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Noida, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":33000,"max_usd":75000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1098},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Bash","optional":false},{"name":"Burp Suite","optional":false},{"name":"CI/CD","optional":false},{"name":"CVSS","optional":false},{"name":"CWE","optional":false},{"name":"Docker","optional":false},{"name":"GCP","optional":false},{"name":"Git","optional":false},{"name":"GraphQL","optional":false},{"name":"Kali Linux","optional":false},{"name":"Kubernetes","optional":false},{"name":"Linux","optional":false},{"name":"Metasploit","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"MobSF","optional":false},{"name":"Nessus","optional":false},{"name":"Nmap","optional":false},{"name":"OpenVAS","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"OWASP ZAP","optional":false},{"name":"Postman","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Rest API","optional":false},{"name":"SOAP","optional":false},{"name":"SQL","optional":false},{"name":"Windows","optional":false},{"name":"Wireshark","optional":false}],"status":"live","first_seen_at":"2026-09-02T00:00:00Z","employer_posted_date":"2026-09-25","last_verified_at":"2026-09-25T20:27:56Z","board_verified":true,"closed_at":null,"days_open":25,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":25},"description":"Job Description - Penetration Tester\nPosition Details\nRole: Penetration Tester\n Experience: 5-7 Years (in Penetration Testing)\nEmployment Type: Full-Time\nDepartment: Information Security / Offensive Security\nAbout the Role\nWe are seeking an experienced and highly skilled Penetration Tester to join our cybersecurity team. The ideal candidate will have deep expertise in offensive security assessments, vulnerability exploitation, application security testing, and advanced attack simulations across enterprise environments. The candidate should possess strong analytical skills, hands-on technical capabilities, and the ability to independently conduct end-to-end penetration testing engagements.\nThe role involves identifying security weaknesses across web applications, mobile applications, APIs, cloud infrastructure, and enterprise networks, while providing actionable remediation guidance aligned with industry best practices and regulatory requirements.\nKey Responsibilities\nExecute manual penetration tests against web, mobile, API, and cloud environments to identify critical security gaps that automated tools often miss.\nDeploy and optimize advanced penetration testing tools and custom scripts to validate the exploitability of discovered vulnerabilities.\nDraft high-quality technical reports featuring detailed remediation guidance and risk-prioritized findings for both technical and executive stakeholders.\nDevelop custom proof-of-concept (PoC) exploits to demonstrate the real-world impact of identified security weaknesses.\nValidate the effectiveness of security patches and configuration changes through structured and rigorous retesting procedures.\nEnhance internal offensive security frameworks and testing methodologies through continuous research and tool improvement.\nApply deep knowledge of network protocols, operating systems, and system architectures to navigate and compromise complex enterprise environments.\nAnalyse and exploit diverse vulnerability classes including XSS, SQL Injection (SQLi), SSRF, RCE, IDOR, Authentication & Authorization flaws, and complex business logic vulnerabilities.\nPerform comprehensive security assessments of REST, SOAP, and GraphQL APIs to ensure secure data exchange and access control mechanisms.\nUtilize professional offensive security toolsets including Burp Suite, Metasploit, Nessus, Nmap, Wireshark, and Kali Linux to conduct full-scope security assessments.\nWrite custom automation and exploitation scripts in Python, Bash, and PowerShell to improve testing efficiency and exploit depth.\nTranslate technical vulnerabilities into business-focused risk narratives through effective technical writing and communication.\nConduct offensive operations across Linux and Windows-based infrastructures to identify environment-specific weaknesses and misconfigurations.\nFollow industry-standard penetration testing methodologies and frameworks including OWASP Testing Guide, MITRE ATT&CK, OSSTMM, PTES, and NIST.\nIndependently manage end-to-end security assessments while maintaining high standards of quality, precision, and professional accountability.\nLead technical audits, assessment activities, and documentation efforts required for CERT-IN empanelment, regulatory audits, and compliance requirements.\nCollaborate with development, infrastructure, DevSecOps, and compliance teams to support remediation and security improvement initiatives.\nRequired Skills & Technical Expertise\nTechnical Skills\nStrong hands-on experience in Web Application, Mobile Application, API, Network, and Cloud Penetration Testing.\nExpertise in vulnerability assessment and manual exploitation techniques.\nStrong understanding of OWASP Top 10, SANS Top 25, CWE, and CVSS scoring methodologies.\nExperience with Active Directory security assessments and privilege escalation techniques.\nKnowledge of cloud security testing across AWS, Azure, and GCP environments.\nUnderstanding of secure authentication mechanisms including OAuth, JWT, SAML, MFA, and session management.\nExperience with source code review and secure coding concepts is preferred.\nStrong scripting and automation skills using Python, Bash, or PowerShell.\nFamiliarity with CI/CD security testing and DevSecOps practices.\nTools & Platforms\nBurp Suite Professional\nMetasploit Framework\nNessus / OpenVAS\nNmap\nWireshark\nKali Linux\nOWASP ZAP\nPostman\nMobSF\nDocker & Kubernetes Security Tools\nGit and Version Control Systems\nEducational Qualification\nBachelor’s degree in Computer Science, Information Security, Cybersecurity, Information Technology, or a related field.\nRelevant industry experience may be considered in lieu of formal education.\nCertifications\nMandatory Certifications (Any One)\nOSCP (Offensive Security Certified Professional)\nOSCE (Offensive Security Certified Expert)\nGPEN (GIAC Penetration Tester)\nCEH (Certified Ethical Hacker)\nPreferred Certifications\nCRTO\nCRTP\nCEH\neCPPT\nCISSP\nPNPT\nGWAPT\nCARTP\nPreferred Candidate Profile\nStrong analytical and problem-solving skills.\nExcellent technical documentation and report-writing capabilities.\nAbility to work independently and manage multiple assessment projects.\nStrong communication and stakeholder management skills.\nResearch-oriented mindset with continuous learning attitude.\nExperience handling enterprise-level VAPT engagements and regulatory assessments.\nFamiliarity with CERT-IN audit requirements and compliance-driven security assessments.\nWhat We Offer\nOpportunity to work on advanced offensive security engagements.\nExposure to enterprise, banking, fintech, healthcare, and cloud security projects.\nCollaborative and technically challenging work environment.\nContinuous learning and certification support.\nCareer growth in cybersecurity consulting and offensive security domains.\nLocation\nAs per organizational requirement","description_format":"text","description_chars":5801,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Continuous learning"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Penetration Testing","IT Outsourcing & Dedicated Teams","Business Process Outsourcing (BPO)","Cloud Consulting & Migration"],"lifecycle":[{"event":"open","at":"2026-09-25T13:02:17Z"}],"liveness":{"score":55,"band":"ok","label":"Likely open","p_open":1,"p_active":0.735,"p_room":0.75,"age_days":24,"expected_fill_days":31,"reasons":["conf:9","win:late","comp:brand"],"computed_at":"2026-09-26T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/3i-infotech-penetration-tester","json_url":"https://alion.io/job/3i-infotech-penetration-tester.json","meta":{"generated_at":"2026-09-27T04:37:06Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3989,"day_limit":5000,"remaining_today":1011,"minute_limit":60,"resets_at":"2026-09-28T00:00:00Z"}}}