1,173,434open jobs
66,192companies
208,404added this week
Browse all
Salary
≈ $16k – $39k per year (Estimated)
Location
Hybrid (Mumbai, India)
Seniority
Middle · 5+ years exp

Confirmed on the employer's own hiring board on Oct 4, 2026. First seen by Alion on Jun 23, 2026. Interactive Brokers scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Interactive Brokers is an automated global electronic brokerage headquartered in Greenwich, Connecticut, giving individual traders, advisors and institutions direct access to stocks, options, futures, currencies and bonds on markets worldwide. Founded by Thomas Peterffy in 1978 and listed on Nasdaq, it builds most of its trading and clearing technology in-house and runs offices in Chicago, Zug, Budapest, Tallinn, Dublin, Mumbai, Hong Kong and London, as well as the ForecastEx event contract exchange. Hiring covers software and platform engineers, client services associates, AML and KYC analysts, finance controllers, quant analysts and interns.
Backed by TCV

About the Role 

We are looking for a Senior Penetration Tester who combines strong offensive testing skills with deep application security and secure code review expertise. This role is for someone who doesn't just test applications from the outside — you can read and reason about source code like a developer, trace vulnerable logic from input to sink, and then convert those code-level findings into real, working security test cases and exploits that prove impact end-to-end. You'll own full-cycle assessments: black-box testing, white-box/source-assisted review, and validation — tying it all together into a coherent risk narrative for engineering and leadership, with an attacker's mindset applied throughout. Exposure to broader red team operations is a plus and will allow you to extend application-layer footholds into wider adversary simulation scenarios. 

Key Responsibilities 

Application Penetration Testing (Black-box & White-box) 

Plan, scope, and execute end-to-end penetration tests on web applications, APIs, and mobile apps using both black-box and source-assisted (white-box) methodologies. 

Perform full attack-surface mapping, auth flows, session management, API contracts, business logic, access control boundaries - before diving into exploitation. 

Chain vulnerabilities together to demonstrate real business impact (e.g., IDOR + broken auth → account takeover; SSRF → internal pivot → sensitive data exposure). 

Validate and retest fixes; ensure remediations actually close the exploited path, not just the symptom. 

Manual Secure Code Review 

Conduct manual, in-depth secure code reviews across languages such as Java, Python, JavaScript/TypeScript (Node.js), Go, C#, and PHP — going beyond automated scanner output. 

Trace data flow from source (user input, external API, file upload, etc.) to sink (DB query, deserialization, template engine, OS command, file system, etc.) to confirm real exploitability and eliminate false positives. 

Identify vulnerability classes including injection attacks (SQL, NoSQL, Command, LDAP, XXE), insecure deserialization, authentication and session flaws, IDOR and broken access control, SSRF, race conditions, cryptographic misuse, and business logic flaws. 

Turning Code Findings into Working Security Tests 

For every significant code-review finding, build a corresponding proof-of-concept, exploit script, or test case that demonstrates exploitability in a running environment — not just a theoretical writeup. 

Develop custom scripts/tools (Python, Go, Bash) to weaponize and automate exploitation of identified code patterns across the codebase (e.g., identifying a vulnerable pattern, then scripting mass validation across multiple endpoints/services). 

Translate secure code review findings into repeatable regression security tests that can be reused across engagements and retesting cycles to catch reintroduction of the same bug class. 

Bridge the gap between "this line of code looks dangerous" and "here's the request/script/payload that proves it," making findings actionable and unambiguous for developers. 

Offensive Tooling & Automation 

Go beyond automated scan output — treat static/dynamic analysis as a recon and target-prioritization step, then manually validate and weaponize findings into working exploits, the way an attacker would triage a leaked or decompiled codebase. 

Build and maintain a personal/team exploit and payload library mapped to recurring vulnerability patterns — reusable proof-of-concepts, request templates, and scripts that turn a static finding into a live, demonstrable attack within minutes, speeding up engagement turnaround. 

Chain application-layer findings into deeper exploitation paths — e.g., using a discovered IDOR or auth flaw to escalate privileges within the app, or an SSRF/file-read bug to pivot into other exposed application components or internal services reachable from the app. 

Continuously stress-test your own exploit library and detection logic against the live application — attempt to bypass existing input validation, WAF rules, and app-layer guardrails to ensure findings reflect genuine adversary capability, not just tool coverage. 

Extending Findings into Red Team Scenarios (Good to Have) 

Use application-layer footholds (e.g., an SSRF, exposed internal endpoint, or leaked credential from source code) as an entry point into broader adversary simulation — pivoting from app compromise toward internal network or Active Directory attack paths where in scope. 

Apply working knowledge of C2 concepts (beaconing, traffic patterns, evasion) to understand how an application-layer compromise could realistically be leveraged for persistence or lateral movement in a full red team engagement. 

Bring an adversary-emulation mindset to engagements — thinking beyond "is this exploitable" to "how would a real threat actor chain this into a larger compromise." 

Reporting & Communication 

Author clear, detailed technical reports that connect the dots: vulnerable code snippet → proof-of-concept/exploit → business impact → remediation guidance. 

Map findings to OWASP Top 10, SANS Top 25, and CWE, with risk ratings and clear reproduction steps. 

Present findings to both engineering teams (code-level detail) and leadership (business risk, executive summary). 

Support developers during remediation — reviewing patches and confirming the fix addresses root cause, not just the trigger. 

Mentorship & Program Development 

Mentor junior pentesters/AppSec engineers on manual code review techniques and exploit development. 

Help mature the internal AppSec/pentest methodology — playbooks, custom tooling, and code-review checklists tailored to the tech stacks in use. 

Stay current with new vulnerability classes, framework-specific CVEs, and emerging exploitation techniques; incorporate them into review checklists and test cases. 

Required Qualifications 

5+ years in penetration testing / offensive security, with strong demonstrable experience in application security testing and manual secure code review (not just automated scanning). 

Proven ability to read and understand source code fluently in at least one major backend language (Java, Python, C#, Go, or JavaScript/TypeScript), enough to trace logic, understand data flow, and spot subtle flaws. 

Track record of converting static findings (from code review) into working dynamic proof-of-concepts — able to go from "vulnerable line of code" to an actual exploit/request/script that proves it. 

Strong scripting/programming skills (Python, Go, Bash, or similar) for building custom test scripts, automation, and exploit tooling. 

Solid understanding of web/API architecture and common vulnerability classes (OWASP Top 10, SANS Top 25, CWE). 

Hands-on experience with web/API application testing toolchains (e.g., Burp Suite Pro, Postman) and static/dynamic code analysis approaches. 

Strong report writing and communication skills, able to explain code-level vulnerabilities to both developers and non-technical stakeholders. 

Preferred Qualifications 

Certifications such as OSWE, OSCP, GWAPT, CRTE, or equivalent — OSWE especially valued given the code-review/exploit-dev focus. 

Prior red team experience — comfort with Active Directory attack paths, lateral movement, privilege escalation, and C2 frameworks (e.g., Cobalt Strike, Sliver, Metasploit) is a strong plus. 

Experience with mobile application security testing (iOS/Android) including static analysis of app binaries/source. 

Knowledge of compliance frameworks (PCI-DSS, ISO 27001, SOC 2) as they relate to application security testing. 

Active participation in bug bounty programs with a strong track record of validated findings is a plus. 

Speaking engagements at security/bug bounty conferences (e.g., DEF CON, Black Hat, Nullcon, c0c0n, BSides) or publishing security research/write-ups is a strong plus. 

Company Benefits & Perks: 

Competitive salary package.

Performance based annual bonus (cash and stocks).

Hybrid working model (3 days office/week).

Group Medical & Life Insurance.

Modern offices with free amenities & fully stocked cafeterias.

Monthly food card & company paid snacks.

Hardship/shift allowance with company provided pickup & drop facility*

Attractive employee referral bonus.

Frequent company sponsored team building events and outings.

* Depending upon the shifts.

**The benefits package is subject to change at the management's discretion.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,173,434 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Mumbai
≈ $7k – $20k per year (Estimated) • In office • 1+ year exp • Chennai
Cybersecurity
Microsoft Entra ID
Apply
≈ $13k – $27k per year (Estimated) • In office • 5+ years exp • Chennai
Cybersecurity
Microsoft Entra ID
Apply
≈ $13k – $29k per year (Estimated) • In office • 5+ years exp • Chennai
Cybersecurity
CyberArk
Apply
≈ $10k – $25k per year (Estimated) • In office • 3+ years exp • Chennai
Cybersecurity
Microsoft Entra ID
Apply
≈ $11k – $26k per year (Estimated) • In office • 3+ years exp • Chennai
Cybersecurity
CyberArk
Apply
≈ $15k – $37k per year (Estimated) • In office • 3+ years exp • Bachelor's Degree • Pune
AI/ML
Red Teaming
Cybersecurity
ISO 27001
PCI DSS
SOC 2
GDPR
HIPAA
CAPA
Management
ServiceNow
Apply
≈ $22k – $57k per year (Estimated) • In office • Bengaluru
AI/ML
Red Teaming
Cybersecurity
OWASP Top 10
Apply
≈ $16k – $40k per year (Estimated) • In office • 3+ years exp • Bengaluru
AI/ML
Red Teaming
DevOps
TCP/IP
DNS
DHCP
Cybersecurity
Burp Suite
Metasploit
Nmap
OWASP Top 10
Active Directory
LDAP
Apply
Hybrid • 3+ years exp • Bachelor's Degree
AI/ML
Red Teaming
DevOps
Splunk
Prometheus
Git
Cortex
Windows
Cybersecurity
Microsoft Sentinel
MITRE ATT&CK
LogRhythm
Cortex XSOAR
SIEM
Management
Confluence
Apply
In office • 3+ years exp • Bachelor's Degree
AI/ML
Red Teaming
Apply
≈ $14k – $35k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Mumbai
AI/ML
LLM
DevOps
Terraform
GCP
Azure
AWS
Kubernetes
Platform Engineering
Shift-Left
IAM
Cybersecurity
ISO 27001
NIST CSF
OWASP Top 10
STRIDE
Shift-Left Security
Threat Modeling
Active Directory
LDAP
OWASP
Apply
≈ $14k – $34k per year (Estimated) • Hybrid • 10+ years exp • Mumbai
DevOps
GCP
Azure
AWS
Cloudflare
Akamai
TCP/IP
DNS
Cybersecurity
ISO 27001
OWASP Top 10
PCI DSS
Zero Trust
Defense in Depth
Least Privilege
Threat Modeling
AWS WAF
Apply
≈ $97k – $270k per year (Estimated) • In office • Internship • Greenwich
AI/ML
Red Teaming
Apply
≈ $121k – $252k per year (Estimated) • Equity • Hybrid • 6+ years exp • Chicago
Cybersecurity
SIEM
Apply
≈ $110k – $215k per year (Estimated) • Equity • Hybrid • 7+ years exp • Greenwich
Cybersecurity
NIST CSF
Apply
≈ $24k – $71k per year (Estimated) • In office • 12+ years exp • Bengaluru • Mumbai
DevOps
Incident Management
Cybersecurity
ISO 27001
SOC 2
GDPR
Apply
≈ $12k – $30k per year (Estimated) • In office • 5+ years exp • Mumbai
DevOps
VMWare
Azure
Incident Management
Windows
Cybersecurity
Active Directory
Management
ServiceNow
Outlook
SharePoint
ITIL
ITSM
Apply
≈ $18k – $48k per year (Estimated) • In office • Mumbai
Python
Bash
AI/ML
MLFlow
Kubeflow
ClearML
InfiniBand
NVLink
DevOps
Ansible
Red Hat
OpenShift
Loki
Prometheus
SLURM
Git
Kubernetes
Ubuntu
Grafana
HPC
Linux
Apply
≈ $9.5k – $24k per year (Estimated) • In office • 4+ years exp • Mumbai
Java
Java
Apache Tomcat
DevOps
Apache HTTP Server
CentOS Stream
Incident Management
Linux
Unix
Apache HTTP Server
Management
Jira
ServiceNow
Apply
≈ $17k – $46k per year (Estimated) • In office • 6+ years exp • Bachelor's Degree • Mumbai
Management
Monday.com
Marketing
Salesforce
Marketo
LinkedIn
Apply
See all jobs
This is one of many
1,173,434 more open roles from verified company boards, updated every day.