This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Penetration Testing Analyst based in India.
This is a senior cybersecurity opportunity within a global Red Team environment focused on uncovering vulnerabilities before real-world adversaries can exploit them.
You will conduct advanced penetration testing across either application security or network security, using both commercial and internally developed tools.
The role combines hands-on offensive security work with client-facing communication and professional security reporting.
You will investigate emerging threats, vulnerabilities, and exploitation techniques to continuously strengthen your testing capabilities.
Your findings will help clients understand security risks, reproduce vulnerabilities, and prioritize effective remediation.
You’ll operate as a technical subject-matter expert while collaborating with experienced security professionals across diverse engagements.
This role is ideal for an accomplished penetration tester who brings strong technical depth, curiosity, analytical thinking, and confident client communication.
Accountabilities
- Conduct advanced application security assessments covering web applications, mobile applications, APIs, and related attack surfaces, or network security assessments including internal and external penetration tests and vulnerability assessments.
- Perform manual exploitation testing using tools such as Nmap, Metasploit, Kali Linux, Burp Suite, and other commercial or internally developed offensive security tools.
- Research emerging threats, vulnerabilities, attack techniques, and exploits to identify new opportunities for advanced security testing.
- Document vulnerabilities, exploitation evidence, reproduction steps, technical impact, and remediation recommendations for client use.
- Produce and deliver professional security assessment reports that clearly communicate findings and risk.
- Lead client-facing meetings throughout engagements, including project kickoffs, high- and critical-severity finding notifications, and close-out discussions.
- Explain technical findings, supporting evidence, testing methodology, reproduction steps, and remediation recommendations to client stakeholders.
- Collaborate with broader security and project teams while independently managing assigned testing activities and deliverables.
- Take ownership of complex technical challenges and contribute knowledge, insights, and best practices to the wider security function.
- Perform additional responsibilities as needed while maintaining a high standard of technical quality and client service.
- Typically 6+ years of relevant professional experience with a Bachelor’s degree, 5+ years with a Master’s degree, 3+ years with a PhD, or equivalent professional experience.
- At least 4 years of hands-on penetration testing experience.
- At least 4 years of practical experience with one or more of Nmap, Metasploit, Kali Linux, or Burp Suite.
- Strong knowledge of application attack vectors, penetration testing methodologies, security testing processes, and common vulnerabilities such as the OWASP Top 10.
- Solid technical understanding of TCP/IP networking and familiarity with operating system administration and internals across Microsoft Windows and Linux.
- Experience with vulnerability and application security testing tools such as NetSparker and AppScan is desirable.
- Working knowledge of SQL and high-level programming languages is a plus.
- An offensive security certification such as CEH, WAPT, GPEN, GWAPT, GAWN, or OSCP is desirable.
- A Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical discipline is preferred, or equivalent professional experience.
- Strong technical communication skills, both written and verbal, with the ability to explain complex security findings clearly to technical and non-technical stakeholders.
- Excellent analytical, troubleshooting, and problem-solving abilities.
- Ability to work effectively as a self-directed individual contributor while collaborating within a larger security team.
- Proactive mindset, strong professional judgment, and willingness to continuously research and develop expertise in emerging threats and offensive security techniques.
- Willingness to travel occasionally, with travel potentially reaching up to 10%.
- Ability to work remotely in India with legal authorization to work in the jurisdiction without requiring employer sponsorship.
- Remote-first working model with the opportunity to work from home.
- Opportunity to conduct real-world penetration testing and advanced offensive security engagements for global clients.
- Exposure to diverse application, network, and technology environments.
- Opportunities to deepen expertise in emerging vulnerabilities, exploits, attack techniques, and security tools.
- Collaborative culture combining technical autonomy with strong team interaction.
- Employee-led diversity and inclusion networks that foster community, education, and advocacy.
- Annual charity initiatives, fundraising activities, and employee volunteer days.
- Global sustainability initiatives supporting environmental responsibility.
- Fitness, trivia, and other employee engagement activities.
- Global wellbeing days and monthly wellbeing webinars and training focused on employee health and wellbeing.

