Remote (India) · Mid Level · Remote
Applicants who checked fit first are 3.1× more likely to hear back
Your score for this role already exists
ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.
No credit card · 1 tap with Google
HIGH
Jobgether is actively reviewing profiles and moving candidates through the pipeline right now.
First 72 hours
Still inside it - posted 2h agoEarly applicants get seen before the pile builds.
Not a repost
The first time we've seen this listing - it hasn't been closed and reopened.
You almost certainly match several of these already. Unlock your skill map to see the matches, the gaps, and what to fix first.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Penetration Testing Analyst 3 based in India.
As a Penetration Testing Analyst 3, you’ll help identify and demonstrate security weaknesses that could be exploited by real-world attackers.
You’ll combine hands-on penetration testing with threat research, vulnerability analysis, and client-facing security consulting.
Depending on your specialization, you’ll focus on application security or network security, using both established and internally developed tools.
You’ll take ownership of testing readiness, coordinate engagement activities, and serve as a key point of contact throughout client projects.
The role involves communicating technical findings to clients and producing clear, actionable security assessment reports.
You’ll work in a remote, collaborative environment alongside security professionals while continuously researching emerging threats and exploitation techniques.
With opportunities to handle complex assessments and contribute to advanced offensive security work, the position offers meaningful technical and professional growth.
Coordinate testing readiness activities, documentation, schedules, dependencies, and information across business, client, and project teams.
Act as a primary point of contact for testing readiness, communicating engagement status and resolving or escalating readiness issues as required.
Use project management tools to track key tasks, responsibilities, timelines, dependencies, and engagement status.
Identify, troubleshoot, and escalate project or technical issues to management when appropriate.
Conduct penetration testing and security assessments in one or more areas, including web applications, mobile applications, APIs, external networks, or internal networks.
Perform manual security testing and advanced exploitation using established penetration testing tools as well as internally developed or self-developed tooling.
Research emerging threats, vulnerabilities, exploits, and attack techniques to strengthen assessment capabilities.
Conduct exploitation testing and document technical findings, evidence, impact, reproduction steps, and remediation recommendations.
Prepare professional security assessment reports that clearly communicate vulnerabilities and exploit information to clients.
Lead client-facing calls throughout engagements, including readiness and troubleshooting sessions, project kick-offs, high- and critical-finding notifications, and close-out reviews.
Explain technical findings, evidence, attack paths, and remediation recommendations clearly to technical and non-technical stakeholders.
Take ownership of new challenges and identify opportunities to improve engagement quality and add value to client outcomes.
Work effectively as both an independent contributor and a collaborative member of a broader security team.
Participate in other security and project activities as required.
Support occasional travel of up to approximately 10%.
3+ years of professional information security experience, including at least 3 years of hands-on penetration testing experience.
Practical experience with at least one major penetration testing platform or tool such as Nmap, Metasploit, Kali Linux, or Burp Suite.
Experience conducting penetration testing in either application security or network security; experience across both areas is advantageous.
For application security, familiarity with web, mobile, or API testing, authentication mechanisms, application attack vectors, and common vulnerabilities such as those covered by the OWASP Top 10.
For network security, understanding of external and internal penetration testing, TCP/IP networking, network appliances, firewalls, WAFs, IDS/IPS, proxies, and network-access validation tools.
Strong understanding of Linux and familiarity with Windows operating systems, administration, and relevant internals.
Ability to research unfamiliar vulnerabilities and attack techniques and translate that knowledge into practical testing approaches.
Strong client-facing communication skills, both written and verbal, with the ability to explain complex security findings clearly.
Excellent analytical, troubleshooting, and problem-solving capabilities.
Strong organizational skills, attention to detail, and the ability to manage multiple priorities and engagement activities.
Self-directed and proactive approach, with the ability to work independently while contributing effectively to a collaborative team.
Professional, accountable, and delivery-focused mindset with a strong commitment to quality.
Ability to learn quickly and adapt in a fast-paced cybersecurity environment.
Offensive security certifications such as CEH, WAPT, GPEN, GWAPT, GAWN, OSCP, or comparable credentials are desirable.
Experience with Nmap scanning, web application authentication, operating system internals, and security testing methodologies is advantageous.
Legal authorization to work in India without requiring employer sponsorship.
Remote-first working model with the opportunity to work remotely from India.
Opportunity to conduct real-world penetration testing and identify vulnerabilities across diverse client environments.
Exposure to application security, network security, threat intelligence, vulnerability research, and advanced exploitation techniques.
Direct interaction with clients throughout security assessment engagements.
Opportunity to continuously develop offensive security skills through research into emerging vulnerabilities and attack methods.
Collaboration with experienced cybersecurity professionals in a global and technically focused environment.
Employee-led diversity and inclusion networks supporting community, education, and advocacy.
Annual charity, fundraising, and employee volunteer initiatives.
Global sustainability initiatives supporting environmental responsibility.
Global fitness and trivia activities.
Dedicated wellbeing days and monthly wellbeing webinars and training.
Inclusive workplace committed to equal opportunity and fair treatment.
Support for reasonable adjustments during the recruitment and selection process where needed.
Free · no signup
Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.
No spam. Just jobs and resources.
Why people use ASAI
Scored, not searched. Every role ranked against your actual profile.
Alerts as often as hourly. Reach new roles while the pile is still small.
Skill gaps, spelled out. See exactly which requirements you don't meet yet.
Verified jobs, only. Say no to ghost jobs. Your time deserves respect.
Keep browsing