Conduct network, web application, cloud, and red-team penetration tests; identify and exploit vulnerabilities; develop proof-of-concept scripts; assess cloud, API, container, Windows, Linux, and Active Directory security; document CVSS-rated findings and remediation plans; verify fixes; and support blue teams with threat and SIEM monitoring insights.
This is a remote position.
Penetration Tester / Ethical Hacker (Offensive Security)
Job Details
- Employment Type: Contract
- Work Mode: Remote
- Location: Offshore
- Total Experience Required: 4 to 8 years
- Relevant Experience Required: 3+ years of dedicated offensive security penetration testing and red teaming experience
- Mandatory Certification: Offensive Security Certified Professional (OSCP) or GIAC Penetration Tester (GPEN)
Job Summary
We are seeking an experienced Penetration Tester to conduct rigorous, multi-vector offensive security assessments against our global network infrastructure, web applications, and cloud environments. The ideal candidate will emulate advanced persistent threat (APT) tactics, discover hidden exploit vulnerabilities, and write technical proof-of-concept reports to help software engineering and infrastructure teams systematically harden corporate defenses.
Key Responsibilities
- Execute comprehensive network and web application penetration tests, utilizing automated scanning suites alongside manual exploration tactics to expose system vulnerabilities.
- Conduct realistic red-teaming simulation campaigns, probing corporate defenses, orchestrating advanced social engineering scenarios, and bypassing physical perimeter monitoring configurations.
- Develop structural custom exploitation scripts (e.g., Python, PowerShell, Bash) to demonstrate vulnerability severity while respecting operational stability guidelines.
- Triage and evaluate cloud infrastructure entry vectors, assessing multi-tenant environment perimeters, microservice containers, API authentication weaknesses, and misconfigured access permissions.
- Document and present highly detailed vulnerability disclosure reports, assigning clear impact scoring (CVSS), defining business risk matrices, and detailing step-by-step technical remediation paths.
- Perform rigorous post-remediation verification sweeps, re-testing patched software frameworks, validated infrastructure updates, and newly implemented defensive logic barriers.
- Collaborate closely with blue-team defensive operators, providing specific threat behavior inputs to optimize SIEM monitoring rules and security log alerts.
Requirements
- 4 to 8 years of core cybersecurity technical experience, with 3+ dedicated years actively performing authorized penetration tests within enterprise frameworks.
- Strong technical mastery of standard exploitation tooling arrays (e.g., Burp Suite Pro, Metasploit, Nmap, Kali Linux), reverse engineering scripts, and manual payload construction.
- Deep structural understanding of the OWASP Top 10 web/API flaws, Windows/Linux kernel security architectures, privilege escalation techniques, and active directory exploit vectors.
- Mandatory certification: OSCP or GPEN.
Preferred Qualifications
- Offensive Security Certified Expert (OSCE) or Advanced Web Attacks and Exploitation (OSWE) credential.
- Experience testing complex enterprise platforms like Salesforce networks, custom SAP endpoints, or specialized Workday database connectivity pipelines.
Similar Jobs
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Develops and executes global medical communications content for oncology, including manuscripts, abstracts, congress materials, literature reviews, educational resources, and multimedia. Ensures scientific accuracy, data quality, compliance, and timely delivery while collaborating with medical, statistics, graphics, compliance, and digital teams. Supports training, project tracking, generative AI adoption, and best-practice development across medical content operations.
Top Skills:
Generative AiExcelMicrosoft PowerpointMicrosoft Word
Artificial Intelligence • Hardware • Information Technology • Machine Learning
Supports 0–13-week assembly and test execution planning by aligning supply, demand, inventory, and manufacturing capacity. Monitors production plans, inventory, fill rates, delivery performance, and at-risk products; analyzes gaps and root causes; coordinates recovery actions across supply chain, manufacturing, and business teams; and contributes to process improvements, system enhancements, and cross-functional planning initiatives.
Financial Services
Coordinate records and information management governance across business and central teams. Implement and monitor records controls for unstructured data, support training and communications, track risks and remediation, and assist with audits and inquiries. The role requires managing workplans, dependencies, governance forums, evidence gathering, stakeholder alignment, and adoption of standardized processes while using AI-enabled approaches to improve recurring inquiry handling.
What you need to know about the Kolkata Tech Scene
When considering the industries shaping India's tech scene, gaming might not immediately come to mind. However, in the last decade, increased internet usage and greater access to mobile devices have catapulted the industry to new heights, with Kolkata-based companies like Virtualinfocom, Red Apple Technologies and Digitoonz, at the forefront, driving the design and animation of new gaming titles for players.


.jpeg)
