Senior Penetration Testing Analyst
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Penetration Testing Analyst based in India.
This is a senior offensive security role focused on identifying and exploiting vulnerabilities that real-world adversaries could target within client environments. You will join a Red Team and conduct advanced penetration testing across application or network security, using both established and internally developed tools. The role combines hands-on technical testing with threat research, vulnerability analysis, and professional security reporting. You will work directly with clients throughout engagements, from project kick-off through critical finding notifications and final remediation discussions. The position offers the opportunity to investigate emerging threats and develop a deeper understanding of new vulnerabilities and exploitation techniques. You will work with significant independence while collaborating with a broader security team in a remote-first environment.
Accountabilities:
- Conduct advanced penetration testing and application security assessments across web applications, mobile applications, APIs, or network environments, depending on your area of specialization.
- Perform external and internal network penetration tests and vulnerability assessments using established methodologies and appropriate offensive security techniques.
- Use and, where appropriate, develop exploitation tools to conduct manual testing and identify vulnerabilities that automated assessments may overlook.
- Research emerging threats, vulnerabilities, attack techniques, and exploits to continuously strengthen penetration testing capabilities.
- Analyze vulnerabilities and exploitation paths, gather supporting evidence, and document findings clearly for client remediation.
- Produce professional security assessment reports that communicate vulnerabilities, exploit details, evidence, reproduction steps, risk context, and remediation recommendations.
- Lead client-facing discussions throughout engagements, including project kick-offs, notifications of high and critical findings, and close-out reviews.
- Explain complex technical findings clearly to clients and provide actionable recommendations for improving their security posture.
- Work independently to manage testing activities and deliverables while collaborating effectively with other members of the security team.
- Contribute to additional security initiatives and perform other responsibilities required to support penetration testing and threat research activities.
- Travel occasionally, with potential travel of up to 10% depending on engagement requirements.
- 7+ years of related professional experience with a Bachelor’s degree, 5+ years with a Master’s degree, 3+ years with a PhD, or equivalent professional experience.
- At least 4 years of professional penetration testing experience.
- At least 4 years of hands-on experience with one or more offensive security tools such as Nmap, Metasploit, Kali Linux, or Burp Suite.
- Experience conducting application security testing, network penetration testing, or both; candidates may specialize in either application or network security.
- Strong knowledge of common application vulnerabilities and attack vectors, including the OWASP Top 10 and established security testing methodologies.
- Solid understanding of TCP/IP networking and practical knowledge of operating system administration and internals across Windows and/or Linux environments.
- Working knowledge of SQL and at least one high-level programming language.
- Offensive security certifications such as CEH, WAPT, GPEN, GWAPT, GAWN, OSCP, or equivalent credentials are valuable.
- Familiarity with additional application security tools such as Netsparker or AppScan is desirable.
- Strong analytical and problem-solving abilities, with a methodical approach to identifying, validating, and documenting vulnerabilities.
- Excellent written and verbal technical communication skills, particularly when explaining complex security findings to clients.
- Ability to work autonomously, take ownership of engagements, and collaborate effectively as part of a larger security team.
- Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical discipline is preferred, or equivalent professional experience.
- Legal authorization to work in India without requiring employer sponsorship.
- Fully remote opportunity with a remote-first working model.
- Potential travel of up to 10% depending on client and engagement requirements.
- Opportunity to work on real-world penetration testing engagements across application and network security.
- Exposure to advanced offensive security techniques, emerging vulnerabilities, threat research, and exploitation methodologies.
- Opportunity to work with both established and internally developed security testing tools.
- Global collaboration with experienced cybersecurity professionals and security research teams.
- Employee-led diversity and inclusion communities supporting connection, learning, and advocacy.
- Volunteer and charitable initiatives that support local communities.
- Global sustainability initiatives and opportunities to contribute to environmental programs.
- Employee wellbeing programs, including wellbeing days, webinars, and health-focused training.
- Fitness, trivia, and other global employee activities designed to encourage connection and engagement.
- An inclusive environment that supports equal opportunity and accommodations throughout the recruitment process.