This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Penetration Testing Analyst based in India.
This is a remote cybersecurity role within a global Red Team environment focused on identifying and exploiting vulnerabilities before real-world attackers can do so.
You will assess client environments across application or network security, using both established and internally developed offensive security tools.
The role combines hands-on penetration testing with client engagement, test-readiness coordination, and professional security reporting.
You’ll investigate emerging threats, vulnerabilities, and exploitation techniques to continuously strengthen your technical capabilities.
You will also communicate critical findings directly to clients and help them understand evidence, reproduction steps, and remediation recommendations.
The position offers a balance of independent technical work and close collaboration with experienced security and project teams.
It is particularly suited to a security professional who combines offensive testing expertise with strong communication, organization, and analytical judgment.
Accountabilities
- Coordinate testing readiness activities, documentation, schedules, dependencies, and information across business, client, and project teams.
- Serve as the primary point of contact for testing readiness, communicate engagement status, and troubleshoot client-side readiness issues.
- Use project management tools to monitor tasks, ownership, timelines, milestones, and overall engagement progress.
- Escalate project or technical issues to management when appropriate and proactively take ownership of new challenges and opportunities to add value.
- Conduct penetration testing focused on either application security-including web applications, mobile applications, and APIs-or network security, including external and internal penetration tests and vulnerability assessments.
- Perform manual exploitation testing using tools such as Nmap, Metasploit, Burp Suite, Kali Linux, and other commercial or internally developed security tools.
- Research emerging threats, vulnerabilities, attack techniques, and exploits to support advanced testing activities.
- Document vulnerabilities, exploitation evidence, reproduction steps, technical findings, and remediation recommendations in professional security assessment reports.
- Lead client-facing calls throughout engagements, including readiness and troubleshooting sessions, project kickoffs, high- and critical-finding notifications, and close-out reviews.
- Work independently while contributing effectively to a broader security team and taking on additional responsibilities as required.
- 3+ years of professional experience in information security, including at least 3 years of hands-on penetration testing experience.
- Practical experience with at least one major penetration testing tool or platform, such as Nmap, Metasploit, Kali Linux, or Burp Suite.
- Strong understanding of offensive security concepts, application attack vectors, security testing methodologies, and common vulnerabilities such as the OWASP Top 10.
- Experience with network security concepts, TCP/IP, network appliances, firewalls, WAFs, IDS/IPS, proxies, routers, and load balancers is highly valuable.
- Familiarity with web application authentication methods, Linux environments, operating system administration, and Windows/Linux internals.
- Strong technical troubleshooting, analytical, and problem-solving abilities.
- Excellent written and verbal communication skills, particularly for client-facing discussions and technical security reporting.
- Strong organizational skills, attention to detail, multitasking ability, and the capacity to manage competing priorities.
- Ability to learn quickly, research unfamiliar threats, and operate effectively in a high-energy, fast-paced environment.
- A proactive, accountable, and professional mindset with a strong commitment to teamwork and delivering high-quality results.
- Offensive security certifications such as CEH, WAPT, GPEN, GWAPT, GAWN, or OSCP are desirable.
- Willingness to travel occasionally, with travel potentially reaching up to 10%.
- Ability to work remotely with legal authorization to work in India without requiring employer sponsorship.
- Fully remote-first working model.
- Opportunity to work on real-world penetration testing and advanced offensive security engagements for global clients.
- Exposure to diverse application and network security environments and emerging cyber threats.
- Collaborative environment combining independent technical ownership with experienced security teams.
- Employee-led diversity and inclusion networks and community initiatives.
- Annual charity, fundraising, and employee volunteering opportunities.
- Global sustainability initiatives and employee engagement programs.
- Fitness, trivia, and other global employee activities.
- Dedicated wellbeing days, webinars, and training focused on employee health and wellbeing.
- Opportunities to continuously develop offensive security expertise through exposure to new vulnerabilities, exploits, tools, and testing methodologies.

