
Posted Today
Penetration Testing
MumbaiOn-siteFull-time
AI Summary
A Penetration Tester independently executes penetration testing engagements on web applications, APIs, networks, and cloud environments, identifying and exploiting vulnerabilities to produce client-ready reports with actionable remediation guidance.
About this role
Penetration Tester (Mid–Senior Level)
Location - Remote - India
Experience Level - 2-5 years
As a Penetration Tester, you will be responsible for executing penetration testing engagements through client delivery with minimal oversight. You will independently perform testing activities, identify and exploit vulnerabilities, and produce high-quality client deliverables with clear, actionable remediation guidance. You will assess web applications, APIs, networks, and/or cloud environments using a combination of automated tools and manual techniques. This includes configuring and operating testing tools, developing proof-of-concepts to demonstrate impact, and clearly documenting findings. You will also participate in client-facing activities such as scoping discussions, kickoff calls, and report reviews, and are expected to communicate technical concepts effectively to both technical and non-technical audiences. In addition to delivery, you will contribute to the overall quality and evolution of the testing program by performing QA, Re-Tests, peer reviews, supporting internal tooling and methodology improvements, and sharing knowledge with other team members.
Must Have: Offensive Security Certification Experience testing web applications and APIs (REST, SOAP, XML, JSON) and thick client
Key Responsibilities:
Location - Remote - India
Experience Level - 2-5 years
As a Penetration Tester, you will be responsible for executing penetration testing engagements through client delivery with minimal oversight. You will independently perform testing activities, identify and exploit vulnerabilities, and produce high-quality client deliverables with clear, actionable remediation guidance. You will assess web applications, APIs, networks, and/or cloud environments using a combination of automated tools and manual techniques. This includes configuring and operating testing tools, developing proof-of-concepts to demonstrate impact, and clearly documenting findings. You will also participate in client-facing activities such as scoping discussions, kickoff calls, and report reviews, and are expected to communicate technical concepts effectively to both technical and non-technical audiences. In addition to delivery, you will contribute to the overall quality and evolution of the testing program by performing QA, Re-Tests, peer reviews, supporting internal tooling and methodology improvements, and sharing knowledge with other team members.
Must Have: Offensive Security Certification Experience testing web applications and APIs (REST, SOAP, XML, JSON) and thick client
Key Responsibilities:
- Execute penetration testing engagements, across web applications, APIs, networks, and cloud environments
- Identify, exploit, and document vulnerabilities with clear supporting evidence and proof-of-concept
- Develop practical, risk-based remediation guidance
- Produce high-quality, client-ready reports
- Participate in client-facing calls including scoping, kickoff, and report reviews
- Perform QA reviews of peer deliverables
- Contribute to internal tools, research, and methodology improvements
- Support and collaborate with team members to maintain delivery quality and consistency
-
Handle sensitive client information with confidentiality and professionalism
Qualifications & Experience: - Strong understanding of networks, web/mobile applications, and common security vulnerabilities (e.g., OWASP Top 10, common CVEs)
- Industry-relevant certifications (SANS, Offensive Security, eLearn Security, etc.)
- Experience testing web applications and APIs (REST, SOAP, XML, JSON)
- Familiarity with modern web frameworks (e.g., Angular, Bootstrap)
- Experience with scripting languages such as Python, Bash, PowerShell, or similar
- Knowledge of vulnerabilities including XSS, SQL Injection, XXE, SSRF, deserialization, file inclusion/path traversal, authentication flaws, and remote code execution
- Ability to develop proof-of-concepts and clearly demonstrate impact
- Strong written and verbal communication skills
- Ability to work independently and as part of a team
Skills
API TestingAuthentication FlawsBashCloud SecurityDeserializationFile InclusionNetwork TestingOffensive Security CertificationOWASP Top 10Path TraversalPenetration TestingPowerShellPythonRemote Code ExecutionSANSSQL InjectionSSRFWeb Application TestingXSSXXE
Explore related jobs
More jobs at Prescient Security
Similar Penetration Testing jobs
Jobs in Mumbai
India - Assistant Manager CLS Operations (Internal Only)ISS Group Holdings Limited · Mumbai, Maharashtra
Business Analystadm-Indicia · Mumbai
Enterprise Account Executive, Industries - BFSIAnthropic · Mumbai, India- Senior Risk Analyst – Data Science & AnalyticsExperian · Mumbai, India
- Manager- Paid SocialWPP Media · Bangalore, India
SOC AnalystWaystone · Mumbai, Maharashtra
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.