5 Ethical Hacking Techniques jobs in Hyderabad
Junior Penetration Testing Engineer

Posted 2 days ago
Job Viewed
Job Description
At Amgen, if you feel like you're part of something bigger, it's because you are. Our shared mission-to serve patients living with serious illnesses-drives all that we do.
Since 1980, we've helped pioneer the world of biotech in our fight against the world's toughest diseases. With our focus on four therapeutic areas -Oncology, Inflammation, General Medicine, and Rare Disease- we reach millions of patients each year. As a member of the Amgen team, you'll help make a lasting impact on the lives of patients as we research, manufacture, and deliver innovative medicines to help people live longer, fuller happier lives.
Our award-winning culture is collaborative, innovative, and science based. If you have a passion for challenges and the opportunities that lay within them, you'll thrive as part of the Amgen team. Join us and transform the lives of patients while transforming your career.
Junior Penetration Testing Engineer
**What you will do**
Let's do this. Let's change the world. In this vital role has a strong focus on ensuring the organization's infrastructure, applications, and systems are secure from external and internal threats. This role is responsible for conducting authorized security tests on IT infrastructure to evaluate the strength of its systems against potential cyberattacks. A variety of automated tools and manual techniques are leveraged to simulate real-world attacks. The penetration tester then works with the organization to prioritize, remediate and report on identified issues, strengthening the overall security posture.
**Roles & Responsibilities:**
+ Assist in penetration testing and security assessments under the supervision of senior engineers.
+ Document findings, providing clear and actionable remediation recommendations.
+ Identify and report vulnerabilities in applications, networks, cloud environments, and infrastructure.
+ Perform hands-on exploitation techniques to validate security weaknesses.
+ Use automated security tools (e.g., Burp Suite, OWASP ZAP, Metasploit, Nmap) and manual testing techniques to identify vulnerabilities.
+ Research emerging cybersecurity threats and contribute to the improvement of penetration testing methodologies.
+ Collaborate with development and security teams to implement secure coding practices and security best practices.
+ Participate in adversarial simulations, red team and purple team exercises as part of security assessments.
+ Support security compliance efforts aligned with industry frameworks (e.g., NIST, ISO 27001, PCI-DSS).
+ Continuously learn and improve technical skills in ethical hacking, scripting, and exploit development.
**What we expect of you**
We are all different, yet we all use our unique contributions to serve patients.
Master's degree and 1 to 3 years of experience in Cybersecurity or information security operations OR
Bachelor's degree and 3 to 5 years of experience in Cybersecurity or information security operations OR
Diploma and 7 to 9 years of experience in Cybersecurity or information security operations
**Must-Have Skills:**
+ Basic knowledge of penetration testing methodologies (e.g., PTES, OWASP Testing Guide).
+ Understanding of network application security, application security, and cloud security.
+ Familiarity with OWASP Top 10, SANS Top 25, and common attack techniques.
+ Experience using security tools such as Burp Suite, Nmap, OWASP ZAP, and Metasploit.
+ Basic proficiency in scripting and automation (e.g., Python, Bash, PowerShell).
**Preferred Qualifications:**
**Good-to-Have Skills:**
+ Experience with **threat intelligence and adversary simulation** .
+ Basic knowledge of **secure coding practices** and defensive security measures.
+ Interest in **red teaming, social engineering, and cloud security testing** .
+ Preferred: eJPT (Junior Penetration Tester)
**Soft Skills:**
+ Curiosity & Continuous Learning - Passion for cybersecurity research and ethical hacking.
+ Analytical Thinking - Ability to identify patterns and security weaknesses.
+ Communication Skills - Ability to document findings and present them effectively.
+ Collaboration & Teamwork - Works well in a team-oriented environment, learning from senior testers.
+ Attention to Detail - Precision in identifying vulnerabilities and reporting them clearly.
+ Problem-Solving Mindset - Ability to analyze and troubleshoot security risks effectively.
**What you can expect of us**
As we work to develop treatments that take care of others, we also work to care for your professional and personal growth and well-being. From our competitive benefits to our collaborative culture, we'll support your journey every step of the way.
In addition to the base salary, Amgen offers competitive and comprehensive Total Rewards Plans that are aligned with local industry standards.
**Apply now and make a lasting impact with the Amgen team.**
**careers.amgen.com**
As an organization dedicated to improving the quality of life for people around the world, Amgen fosters an inclusive environment of diverse, ethical, committed and highly accomplished people who respect each other and live the Amgen values to continue advancing science to serve patients. Together, we compete in the fight against serious disease.
Amgen is an Equal Opportunity employer and will consider all qualified applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or any other basis protected by applicable law.
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
Junior Penetration Testing Engineer
Posted today
Job Viewed
Job Description
About Claranet
Founded at the beginning of the dot.Com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries.
At Claranet, we’re experienced in implementing progressive technology solutions which help our customers solve their epic business challenges. We’re committed to understanding their problems, delivering answers quickly, and making a lasting impact to their business.
We are agile, focused and experienced in business modernisation. Our approach helps customers make genuine, significant shifts in their business strategy, to deliver financial savings, boost innovation, and create a resilient business. We continually invest in our people and the latest technologies, so our customers get peace of mind knowing that they have access to the best talent and services.
In the UK we have over 500 staff working in London, Gloucester, Warrington, Bristol, and Leeds or as homeworkers. we have 130 staff in India working for international projects.
Working For Claranet
Here at Claranet we pride ourselves on going the extra mile for and with our employees (yes, we really mean with). We offer an extensive benefits package that you can tailor to your needs, inclusive of a matching contribution pension scheme, healthcare, insurance.
Claranet are one of the 10 founding members of TC4RE (Technology Community for Racial Equality.) Being a part of a group of leading UK technology organisations, we are dedicated to building a more diverse and inclusive workforce.
Our Vision
Our vision is to become the most trusted technology solutions partner;
renowned for being the best and brightest, having lasting impact with our customers and delivering exceptional returns to our stakeholders.
Position Summary
Claranet Cyber Security is a world class business unit within Claranet, designed to give customers access to market-leading information security expertise and services spanning;
penetration testing, compliance consulting, training and managed services.
The primary function of the Penetration Tester in the CST team is to continually review the customers’ defined scope for vulnerabilities, identify additional targets that should be included in the scope, and report these to the client in a timely, accurate, and comprehensive manner. The Penetration Tester is also responsible for pre-engagement activities including scoping, statements of work, working with customers to determine their testing requirements and restrictions, on boarding customers into the service and contribute to the service improvement and further development.
To provide the best services to our clients, we need the best people working with us. With outstanding support from the business, all of our penetration testers will gain the experience needed to become the best they can be.
Our team is growing, and we need inspiring people to join us at all levels and help us to continue building a world leading cyber security operation whilst benefiting from a truly unique opportunity to fulfil their potential.
Essential Roles & Responsibilities
The Continuous Security Testing service is a consultant led vulnerability identification and verification service which makes use of automated vulnerability scanning along with significant manual testing against a broad scope in a continuing engagement. The purpose of the service is to continually monitor a customer’s external attack surface for new vulnerabilities, changes in the scope of the attack surface, and proactively inform customers of discovered issues along with recommended remediation;
with the overall aim ofreducing the lifetime of each vulnerability. Manual testing includes identification of issues which automation alone could not identify, exploitation of all issues, often chaining multiple findings together in order to determine the true impact of vulnerabilities for the customer.
Key Responsibilities:
- Manual identification and exploitation of vulnerabilities
- Manual verification and exploitation of scanner findings
- Detailed analysis of issues identified and exposure for the customer including proof of concept, reproduction steps, and recommended remediation
- Communication of findings to the customer in a detailed, accurate and manageable manner both orally and through written vulnerability/scope notifications and periodic summaries
- Continual professional development to maintain and develop knowledge and technical competencies
- Maintain professional technical qualifications to demonstrate competency to our clients
- Undertaking projects and support tasks as appropriate to the role
Progression:
During mentoring and experience progression, the Associate Penetration Tester will be tasked with:
- Pre-engagement activities including scoping of assessments and statements of work and determining customer requirements and restrictions
- Onboarding customers into the service including configuration of continual scanning and liaising with customer to resolve issues which may reduce the effectiveness of scanning
- Monitoring of the customers’ external perimeter for changes, and proactive discovery of new targets to include within the customer’s scope
Essential Technical
Core computing skills including but not limited to:
- Networking fundamentals – understanding of OSI Model, TCP/IP, HTTP, DNS, SMB, SMTP and relevant tools
- Microsoft Windows and Office proficiency along with proficiency in one or more Linux distributions
Good knowledge of web application technologies and security assessment including but not limited to:
- REST APIs, SOAP APIs, XML and JSON formats
- Vulnerability identification and exploitation (not limited to OWASP Top 10)
- Experience with common assessment tools such as MITM proxies (e.G. Burp Suite Pro) and SQLMap
- Good knowledge of internal and external infrastructure technologies and security assessment including but not limited to:
Identification and exploitation of misconfigurations or known vulnerabilities in common enterprise infrastructure and services (Windows Domains, Linux servers, virtualisation, databases, switches/routers, etc)
- Windows and Linux Sandbox/Desktop Breakout
Knowledge of a scripting language such as Python (preferred), Ruby, PowerShell, or Bash, for the development of new, or editing existing, tools
Essential General
- Must be self-motivated and able to work in an independent manner as well as part of a team
- Excellent written and oral communications skills
- Positive, collaborative and enthusiastic
- Appetite to shadow, train and develop to improve capabilities into all areas of security testing
In Addition, The Following Are Highly Desirable:
- CPSA - CREST Practitioner Security Analyst (or above)
- Public speaking experience
- A related Bachelor’s degree
- Experience with live bug bounties, particularly where automation has been implemented
- Knowledge of Open Source Intelligence gathering techniques. Including but not limited to use of Google dorks, DNS, domain registration, certificate transparency, and other public sources of information
Penetration Testing Team Lead
Posted today
Job Viewed
Job Description
About NopalCyber
NopalCyber makes cybersecurity manageable, affordable, reliable, and powerful for companies that need to be resilient and compliant. Through Managed Extended Detection and Response (MXDR), Attack Surface Management (ASM), Breach and Attack Simulation (BAS), and Advisory Services, we fortify our clients’ cybersecurity across both offense and defence.
Our AI-driven Nopal360° platform, NopalGo mobile app, and proprietary Cyber Intelligence Quotient (CIQ) enable organizations to quantify, track, and visualize their cybersecurity posture in real time. We democratize enterprise-grade security operations for organizations of all sizes by lowering the barrier to entry while raising the bar for security and service.
Location : Nopal Cyber, Hyderabad (Work from Office, 5 Days a Week)
Employment Type : Full-time
Key Responsibilities
- Perform advanced Vulnerability Assessment and Penetration Testing (VAPT) across external infrastructure, internal networks, web and mobile applications, APIs, and cloud environments (AWS, Azure, GCP).
- Conduct CIS Benchmark-based hardening assessments and implementations across operating systems (Windows, Linux), databases, middleware, network devices, and cloud platforms.
- Deliver customized hardening guides and security baselines mapped to client-specific compliance requirements and regulatory frameworks.
- Execute Dynamic Application Security Testing (DAST) on web and API applications (both authenticated and unauthenticated) using enterprise-grade tools;
analyze, validate, and prioritize findings with actionable remediation guidance. - Run Breach and Attack Simulation (BAS) scenarios to test resilience against real-world adversary tactics, techniques, and procedures (TTPs).
- Prepare comprehensive technical reports and executive-level summaries highlighting vulnerabilities, attack paths, misconfigurations, and compliance gaps.
- Continuously research emerging attack vectors, zero-day vulnerabilities, DAST methodologies, and new CIS benchmark updates to refine assessment strategies.
- Contribute to Ransomware Resiliency Assessments (RRA) by simulating ransomware behaviors and evaluating control effectiveness.
Required Skills & Experience
- 8–12 years of direct, hands-on cybersecurity consulting experience, with deep expertise in VAPT, CIS benchmarking, and application security testing (DAST).
- Proven track record performing end-to-end penetration tests and dynamic application security scans using industry tools such as Burp Suite Pro, OWASP ZAP, Nessus, Qualys, Netsparker, Acunetix, and custom scripts.
- Strong understanding of web application security flaws (OWASP Top 10, API security issues, authentication/authorization flaws, injection attacks, deserialization, SSRF, RCE, etc.) and ability to exploit and document them.
- Solid understanding of network protocols, operating system behaviors, and common application security principles relevant to modern IT environments.
- Hands-on experience with CIS Benchmark implementation and verification across diverse platforms, ensuring alignment with client compliance mandates.
- Familiarity with BAS tools and adversary emulation frameworks to measure detection and response maturity.
- Proficiency in scripting/automation (Python, PowerShell, Bash) to extend testing capabilities or validate findings.
- Working knowledge of security architecture frameworks (e.G., SABSA) and threat modeling methodologies (e.G., STRIDE, kill chains, attack trees) to support risk-informed vulnerability assessments, hardening efforts, and remediation planning.
- Ability to write and present detailed remediation reports, security recommendations, and compliance-aligned hardening outputs.
- Strong communication skills to convey technical findings to technical and executive stakeholders.
Educational Qualifications
- Bachelor’s degree in engineering, Computer Science, or related discipline.
- CEH Certification (Mandatory) plus one or more advanced certifications:
- OSCP (Offensive Security Certified Professional)
- eCPPT (eLearn Security Certified Professional Penetration Tester)
- CompTIA Pentest+
- CRTP / CRTE (Certified Red Team Professional/Expert)
- CIS-CAT Pro Assessor or equivalent CIS Benchmark credentials
- Familiarity with MITRE ATT&CK and adversary simulation frameworks.
Personal attributes
- Self-starter and quick learner requiring minimal ramp-up
- Excellent written, oral, and interpersonal communication skills
- Highly self-motivated, self-directed, and attentive to detail
- Ability to effectively prioritize and execute tasks in a high-pressure environment
Sr. Security Engineer, Penetration Testing

Posted 2 days ago
Job Viewed
Job Description
**Who We Are.**
When we say, "the stuff dreams are made of," we're not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth. Behind WBD's vast portfolio of iconic content and beloved brands, are the _storytellers_ bringing our characters to life, the _creators_ bringing them to your living rooms and the _dreamers_ creating what's next.
From brilliant creatives, to technology trailblazers, across the globe, WBD offers career defining opportunities, thoughtfully curated benefits, and the tools to explore and grow into your best selves. Here you are supported, here you are celebrated, here you can thrive.
**Job Responsibilities**
+ Execute penetration testing engagements against a variety of web applications/ services and software .
+ Develop and execute attack strategies to simulate real-world attacks by threat actors.
+ Ability to identifying and exploiting vulnerabilities in computer systems, networks, and applications to simulate attacks by threat actors.
+ Analyze and report on the results of security assessments and make recommendations to improve the security posture of the organization.
+ Advise management about noncompliance with defined standards in applications tested.
+ Partner with developers to drive improvement in application security as a result of security assessment engagements .
+ Provide clear communication on the issue to developers and verify the efficacy of the ' fix ' .
+ Provide actionable remediation feedback for findings and/or long-term risk mitigation guidance .
+ Provide guidance and recommendations to other teams to improve the security of products.
+ Demonstrate deep understanding of computer networks, operating systems, databases, web applications, and mobile applications.
+ Experience with Secure software development lifecycle, distributed systems and security protocols.
+ Create custom tools and scripts to automate testing and make the process more efficient.
+ Support and maintain tools used for penetration testing and security assessments .
+ Develop other security engineers .
+ Must be based in the WBD's office, minimum three days/week .
**Qualifications & Experiences:**
+ A Bachelor's degree in Computer Science , Cybersecurity, or other related fields, from an accredited university or an equivalent professional experience may suffice in lieu of a Bachelor's degree.
+ Minimum of 5 years of experience in penetration testing, code review, bug bounty hunting, or red teaming/capture the flag experience.
+ Experience in scripting in Python or other languages to build automation tools
+ Minimum of 5 years of professional experience with security engineering practices such as in web application security, network security, authN / authZ protocols, cryptography, automation, and other software security.
+ Team player with strong communication skills
**If you:**
+ are excited to work in an international, fast-paced, multi-faceted media company.
+ are comfortable ensuring timely escalation, responsiveness and follow through to meet deadlines.
+ are knowledgeable of, and understand, the risk-based business impact approach to cybersecurity.
+ are actively questioning and influencing actions needed to attain goals and targets.
+ are comfortable driving initiatives forward without having direct control of staff.
Then help us create the future with one of the world's largest media & entertainment companies.
**How We Get Things Done.**
This last bit is probably the most important! Here at WBD, our guiding principles are the core values by which we operate and are central to how we get things done. You can find them at along with some insights from the team on what they mean and how they show up in their day to day. We hope they resonate with you and look forward to discussing them during your interview.
**Championing Inclusion at WBD**
Warner Bros. Discovery embraces the opportunity to build a workforce that reflects a wide array of perspectives, backgrounds and experiences. Being an equal opportunity employer means that we take seriously our responsibility to consider qualified candidates on the basis of merit, regardless of sex, gender identity, ethnicity, age, sexual orientation, religion or belief, marital status, pregnancy, parenthood, disability or any other category protected by law.
If you're a qualified candidate with a disability and you require adjustments or accommodations during the job application and/or recruitment process, please visit our accessibility page ( for instructions to submit your request.
VP, Application Security & Penetration Testing
Posted today
Job Viewed
Job Description
Role Overview
As VP/AVP – Offensive security services, you will provide strategic and technical leadership for NopalCyber’s Offensive Security practice. You will lead and evolve core services such as Penetration Testing, Red Teaming, Application Security Assessments, BAS, AI Security and Threat Simulation. This role requires deep technical expertise, engagement leadership, and the ability to influence C-level clients while driving operational excellence across service delivery.
You will be accountable for the scaling, maturity, and quality of offensive security services across multiple client environments, and responsible for shaping the offensive security roadmap, delivery methodologies, and team capability development.
Key Responsibilities
Own and lead the Offensive Security & VAPT function, including service line P&L, strategic delivery roadmap, team management, and client satisfaction.
Architect and oversee enterprise-scale VAPT and red team engagements, driving delivery excellence across infrastructure, applications, APIs, mobile, and cloud environments.
Engage directly with senior client stakeholders (CISOs, CTOs, Risk Leaders) to translate business risk into actionable technical assessments and recommend mitigation strategies.
Define testing frameworks and reusable methodologies to standardize and elevate delivery across projects, including red teaming, threat emulation, and advanced attack simulations.
Direct a high-performing offensive security team, including Red Teamers, AppSec specialists, and security testers, ensuring their continuous development and engagement.
Lead strategic threat modeling and secure design reviews in collaboration with clients' architecture and engineering teams, integrating security into early lifecycle stages.
Govern quality of deliverables, including technical findings, risk summaries, and executive-ready reports, ensuring alignment with business impact and remediation feasibility.
Drive operational excellence across testing engagements, ensuring timelines, SLAs, and KPIs (e.G., MTTR, false positive rate, TTP coverage) are consistently met or exceeded.
Spearhead R&D initiatives to evaluate emerging threats, tools, and offensive capabilities relevant to client environments and evolving attack surfaces.
Collaborate with cross-functional internal teams (MXDR, GRC, Incident Response, Product) to align offensive security outputs with broader risk and advisory services.
Represent NopalCyber at industry forums, client executive reviews, and security advisory boards as a trusted expert in offensive cybersecurity.
Required Qualifications
Bachelor's degree in Engineering, Computer Science, or a related field;
a Master’s is preferred.
15–18 years of experience in cybersecurity with at least 5 years in leadership roles across VAPT, Red Team, or Application Security domains.
Demonstrated experience managing technical delivery and strategic outcomes for multiple clients or large-scale programs.
Preferred Certifications
Mandatory: OSCP, CEH
Highly Desirable: OSCE, OSWE, GPEN, GWAPT, GCIH, GXPN, CISSP
Desired Skills
In-depth understanding of modern attack vectors, OWASP Top 10, MITRE ATT&CK, and real-world exploitation techniques.
Strong command of tools such as Burp Suite Pro, Cobalt Strike, Metasploit, Nmap, Kali Linux, AppDetective, and WebInspect.
Proficiency in cloud security testing across AWS, Azure, or GCP;
experience with containerized and microservices-based environments.
Hands-on exposure to reviewing or attacking applications built using C++, Java, Python, Go, JavaScript, and working within Kubernetes or CI/CD pipelines.
Capability to present complex technical findings in clear, business-relevant language to executive stakeholders.
Leadership Attributes
Strategic thinker with a track record of scaling cybersecurity programs or service lines.
Proven ability to lead, mentor, and retain high-performing technical teams.
Exceptional client engagement and communication skills.
Ability to influence and collaborate across teams and functions to drive security outcomes.
#PenetrationTesting #RedTeamOperations #ApplicationSecurity #OffensiveSecurity #CybersecurityLeadership #CloudSecurity #ThreatModeling #OWASP #StakeholderManagement
#OSCP #MITREATTACK
Be The First To Know
About the latest Ethical hacking techniques Jobs in Hyderabad !