Remote (India) · Mid Level · Remote
Applicants who checked fit first are 3.1× more likely to hear back
Your score for this role already exists
ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.
No credit card · 1 tap with Google
HIGH
Jobgether is actively reviewing profiles and moving candidates through the pipeline right now.
First 72 hours
Still inside it - posted 1h agoEarly applicants get seen before the pile builds.
Not a repost
The first time we've seen this listing - it hasn't been closed and reopened.
You almost certainly match several of these already. Unlock your skill map to see the matches, the gaps, and what to fix first.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Penetration Testing professional based in India.
This remote role offers the opportunity to conduct hands-on security assessments across web applications, APIs, networks, and cloud environments.
You will independently execute penetration testing engagements, identify vulnerabilities, and demonstrate their real-world impact through practical proof-of-concepts.
The position combines automated security tooling with manual testing techniques to uncover complex and meaningful security weaknesses.
You will translate technical findings into clear, actionable remediation guidance and polished client-ready reports.
The role also includes direct interaction with clients through scoping discussions, kickoff meetings, and report reviews.
Beyond individual engagements, you will contribute to quality assurance, peer reviews, internal research, tooling, and improvements to testing methodologies.
It is well suited to a security professional who combines strong offensive security skills with clear communication, independence, and a collaborative mindset.
Execute penetration testing engagements across web applications, APIs, networks, and cloud environments with minimal supervision.
Assess applications and infrastructure using a combination of automated tools and manual testing techniques.
Identify, validate, exploit, and document security vulnerabilities with clear evidence and practical proof-of-concepts.
Evaluate vulnerabilities across areas such as authentication, authorization, injection, XSS, SQL injection, XXE, SSRF, deserialization, file inclusion, path traversal, and remote code execution.
Develop practical, risk-based remediation recommendations that help clients address identified security weaknesses.
Configure and operate penetration testing tools and develop supporting scripts or tooling where appropriate.
Produce accurate, high-quality, client-ready penetration testing reports with clear technical findings and business-relevant context.
Participate in client-facing activities, including scoping discussions, project kickoff calls, technical discussions, and report reviews.
Perform quality assurance reviews and peer reviews of security assessment deliverables.
Contribute to internal security research, tooling, testing methodologies, and continuous improvement initiatives.
Collaborate with other security professionals to maintain consistent delivery quality and share technical knowledge.
Handle sensitive client information responsibly, maintaining confidentiality and professionalism throughout engagements.
2–5 years of professional experience in penetration testing, offensive security, or a closely related cybersecurity discipline.
Industry-recognized offensive security certification or equivalent practical experience; certifications from organizations such as SANS, Offensive Security, or eLearnSecurity are valued.
Strong practical experience testing web applications and APIs, including REST, SOAP, XML, and JSON-based services.
Experience with thick-client applications and familiarity with modern web technologies and frameworks such as Angular and Bootstrap.
Strong understanding of computer networks, web and mobile applications, common security vulnerabilities, and established security frameworks such as the OWASP Top 10.
Knowledge of common CVEs and the ability to assess and exploit vulnerabilities in realistic environments.
Experience with vulnerabilities including XSS, SQL injection, XXE, SSRF, insecure deserialization, file inclusion/path traversal, authentication flaws, and remote code execution.
Ability to develop proof-of-concepts that clearly demonstrate the potential impact and exploitability of identified vulnerabilities.
Proficiency with scripting or automation languages such as Python, Bash, PowerShell, or similar.
Strong written and verbal communication skills, with the ability to explain technical security concepts to both technical and non-technical audiences.
Ability to work independently with limited oversight while also collaborating effectively within a distributed security team.
Strong attention to detail, analytical thinking, and commitment to producing accurate, high-quality client deliverables.
Fully remote working opportunity within India.
Full-time employment.
Opportunity to work on diverse penetration testing engagements across applications, APIs, networks, and cloud environments.
Exposure to real-world cybersecurity challenges and a broad range of technologies and attack surfaces.
Opportunities to contribute to security research, internal tooling, and testing methodology improvements.
Collaborative environment with opportunities for peer learning, technical knowledge sharing, and professional development.
Client-facing experience across security assessments, scoping, kickoff sessions, and report reviews.
Opportunity to strengthen offensive security expertise while working on varied client environments.
Free · no signup
Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.
No spam. Just jobs and resources.
Why people use ASAI
Scored, not searched. Every role ranked against your actual profile.
Alerts as often as hourly. Reach new roles while the pile is still small.
Skill gaps, spelled out. See exactly which requirements you don't meet yet.
Verified jobs, only. Say no to ghost jobs. Your time deserves respect.
Keep browsing