486 Penetration Tester jobs in India
Penetration Tester

Posted 2 days ago
Job Viewed
Job Description
At IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's most challenging problems? If so, lets talk.
About Business Unit :
IBM's Cloud and Cognitive software business is committed to bringing the power of IBM's Cloud and Watson/AI technologies to life for our clients and ecosystem partners around the world. IBM provides you with the most comprehensive and consistent approach to development, security and operations across hybrid environments-with complete software solutions for business and IT operations, development, data science, security, and management. Our experts and software capabilities help organizations develop applications once and deploy them anywhere, integrate security across the breadth of their IT estate, and automate operations with management visibility. With IBM, you also have access to new skills and methods, governance and management approaches, and a deep ecosystem of industry experts and partners.
Wonder if IBM is the one for you? :
In a world where technology never stands still, we understand that, dedication to our clients success, innovation that matters, and trust and personal responsibility in all our relationships, lives in what we do as IBMers as we strive to be the catalyst that makes the world work better.
Being an IBMer means you'll be able to learn and develop yourself and your career, you'll be encouraged to be courageous and experiment everyday, all whilst having continuous trust and support in an environment where everyone can thrive whatever their personal or professional background.
Our IBMers are growth minded, always staying curious, open to feedback and learning new information and skills to constantly transform themselves and our company. They are trusted to provide on-going feedback to help other IBMers grow, as well as collaborate with colleagues keeping in mind a team focused approach to include different perspectives to drive exceptional outcomes for our customers. The courage our IBMers have to make critical decisions everyday is essential to IBM becoming the catalyst for progress, always embracing challenges with resources they have to hand, a can-do attitude and always striving for an outcome focused approach within everything that they do.
Are you ready to be an IBMer?
About IBM :
IBM's greatest invention is the IBMer. We believe that through the application of intelligence, reason and science, we can improve business, society and the human condition, bringing the power of an open hybrid cloud and AI strategy to life for our clients and partners around the world.Restlessly reinventing since 1911, we are not only one of the largest corporate organizations in the world, we're also one of the biggest technology and consulting employers, with many of the Fortune 50 companies relying on the IBM Cloud to run their business.At IBM, we pride ourselves on being an early adopter of artificial intelligence, quantum computing and blockchain. Now it's time for you to join us on our journey to being a responsible technology innovator and a force for good in the world.
**Your role and responsibilities**
Product-Security Technology Centre is responsible for ensuring that IBM products are secure by conducting timely Security reviews, penetration testing and following SPbD practices. As a penetration tester you will perform security testing of IBM product and SAAS offerings in development and production environment. You will also closely work with IBM product development teams to strengthen the security posture of their products by participating in threat model, source code security testing and share best practices / lessons learnt for secure coding/design.
Key responsibilities
* Plan the penetration test
* Select, design and create appropriate tools for testing
* Perform the penetration test on computer systems, networks, web-based and mobile applications
* Document your methodologies, findings
* Gather the data intelligence not only from the output of the automated penetration tools but also from information gathered from interaction with product teams , previous results , threat model and source code scanning inputs.
* Review your findings and feedback to development teams
* Analyse the outcomes and make recommendations for security improvements
* Carry out application, network, systems and infrastructure penetration tests
* Review physical security and perform social engineering tests where appropriate
* Evaluate and select from a range of penetration testing tools
* Keep up to date with latest testing and ethical hacking methods
* Deploy the testing methodology and collect data
* Report on findings to a range of stakeholders
* Make suggestions for security improvements
* Enhance existing methodology material
**Required technical and professional expertise**
* Experience - More than 5years in Cybersecurity
* Web Application Testing
* Basic understanding of HTTP Protocol
* HTTP Methods, Request/Response Headers, Cookies, TCP/IP connections over HTTP etc.
* Basic understanding of HTML/JavaScript
* Good Understanding of security vulnerabilities, OWASP Top 10 vulnerabilities
Automated Testing
* Must have knowledge of at least one of IBM AppScan OR BurpSuite scanner. (Good to have knowledge of both the tools.)
* Should be able to configure automated scanner (such as Login sequence, manually exploring critical flaws, Policy customization, scan throttling, etc.) to perform successful scan.
* Assessment of scanner results and intelligently identifying false positives from the scan results.
* Knowledge of Burp features mainly, Spider, Intruder, Scanner, Repeater and Extender.
Manual Testing.
* Should be able to understand the above mentioned OWASP Top 10 categories to perform manual testing.
* Flaws like, Authentication (session management) testing, CSRF, business logic testing which are not detected by an automated scanner must be identified using manual testing.
* Understanding of the workflow of the application and identifying the entry points to detect possible vulnerabilities.
**Preferred technical and professional experience**
* Webservice Testing
* SOAP/REST APIs testing.
* Configuring cURL commands and POSTMAN tool to capture the request in automated scanner.
Network Testing
* Basic understanding of networking protocols such as TCP, UDP, DNS, DHCP etc.
* Basic understanding of network devices like router, switches, firewall/IDS/IPS etc.
* Network scanning tools such as Nessus, Nmap, Metasploit etc.
* Exploitation and Post Exploitation of network vulnerabilities.
* Threat Model and Source code security scanning
* Perform/Participate in threat model creation/design or review
* Perform source code security scanning using (SAST) tools like Sonarqube, AppScan, Mend and other popular open-source tools.
* Security Certifications
* Any of the security certifications such as CEH, ECSA, EWPT, EWPTX, OSCP, GPEN, GWAPT etc
IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
Penetration Tester
Posted 1 day ago
Job Viewed
Job Description
Job Purpose
As a Senior Penetration Tester, your primary role is to assess and enhance the security of our information systems, networks, and applications through comprehensive penetration testing and vulnerability assessments. You will work closely with our internal product teams to identify weaknesses in their systems and provide actionable recommendations for improvement. Your expertise will help safeguard sensitive data and protect our customers from potential cyber threats. Additionally, you will be responsible for coordinating penetration tests with third-party vendors when required.
Duties and Responsibilities
o Conduct penetration tests on a wide range of digital products, including networks, web, and mobile applications, to identify vulnerabilities and security weaknesses.
o Collaborate with internal product teams to understand their set-ups, goals, and constraints.
o Effectively communicate findings and solutions to technical and non-technical stakeholders.
o Prepare detailed and clear reports documenting findings, reproduce steps, and recommended remediation steps, ensuring the internal product teams understand the security implications.
o Work with cross-functional teams, including security engineers and developers to help them to implement security measures and resolve identified vulnerabilities.
o When your schedule is constrained, coordinate, and manage penetration tests with third-party vendors, ensuring high-quality and timely delivery.
o Contribute to the development and improvement of our testing methodologies, processes, and tools.
o Stay up to date with the latest threats, vulnerabilities, and exploits and develop new testing techniques as necessary.
o Conduct security tests based on products security requirements.
o
Authorities
o Authorized to conduct penetration tests and security tests on selected digital products.
o Authorized to make recommendations for remediation actions based on test results.
o Authorized to engage with internal product teams to discuss findings and recommendations.
o Authorized to coordinate and manage penetration tests with third-party vendors if needed.
Qualifications
o Bachelor’s degree in computer science/engineering, information security, or a related field.
o Proven experience in penetration testing, vulnerability assessment, and security testing with a minimum of 8 years in a similar role.
o Proven track record of conducting successful penetration tests for a variety of organizations and industries.
o Industry-recognized certifications such as Offensive Security Certified Professional (OSCP), GIAC Penetration Tester (GPEN) certifications, or similar qualifications are highly desirable.
o Demonstrated experience in vulnerability research (e.g., CVEs) is a plus.
o Experience in designing, developing, and executing customized penetration testing methodologies.
o Familiarity with various tools and frameworks used in penetration testing, such as Metasploit, Burp Suite, Nessus, Nmap etc.
o Strong knowledge of operating systems (Windows, Linux, and mobile platforms), databases, and web technologies.
o A deep understanding of common security protocols and technologies, including firewalls, intrusion detection/prevention systems, SSL/TLS.
o Programming skills and experience with languages such as Bash, Python, and PowerShell
o The ability to provide clear, comprehensive, and actionable reports on penetration test findings, including recommendations for remediation.
o Exceptional written and verbal communication skills to effectively convey technical information to both technical and non-technical stakeholders.
Penetration Tester
Posted 1 day ago
Job Viewed
Job Description
Penetration Testers - Junior and Senior/Lead
Location:
In Office, Ahmedabad, Gujarat, India (not remote)
Full-time
Salary: Up to ₹12.5L (1,250,000) INR per year for Senior/Lead
Must undergo background check and security clearance
Candidates must already have the right to work and live in India
About Asite
Asite’s vision is to connect people and help the world build better.
Asite’s platform enables organizations working on large capital projects to come together, plan, design, and build with seamless information sharing across the entire supply chain.
Asite SCM is our supply chain management solution, which helps owners and Tier-1 contractors to integrate and manage their extended supply chain for delivering on capital projects.
Asite PPM is our project portfolio management solution, which gives you and your extended supply chain shared visibility of your capital projects through one common data environment.
Together they enable organizations to build digital engineering teams that can deliver digital twins and just plain build better.
The company is headquartered in UK (London) and has regional offices in US (New York and Houston), UAE (Dubai), Australia (Sydney), China (Hong Kong) and India (Ahmedabad).
Job Summary:
We are seeking two Penetration Testers - Junior and Senior/Lead - to join our team of security professionals.
As a senior/lead penetration tester, you will be responsible for conducting comprehensive penetration testing on web applications, mobile and desktop apps, APIs, infrastructure, and other systems such as IoT devices.
You will utilize your expertise in threat modelling, automation of testing, and advanced techniques to identify vulnerabilities and provide actionable recommendations to improve the overall security posture of Asite SDLC and systems.
You will manage a small team that you also must mentor and guide in the best practices and help grow at both professional and managerial level.
You’ll report to the Information Security Officer ME & APAC based in India) and to the CISO (based in London)
You must have a passion for knowledge sharing and continuous learning.
You are willing to undergo background checks and Security Clearance.
Key Responsibilities:
- Conduct thorough threat modelling, risk assessments and vulnerability scanning of web applications, mobile and desktop apps, APIs, infrastructure, and other systems
- Identify and exploit vulnerabilities using various penetration testing tools, techniques, and methodologies – PTES, NIST 800-115, OWASP
- Develop and maintain a comprehensive understanding of systems, including architecture, design patterns, and application logic
- Design and implement effective threat models to identify potential entry points for attackers using STRIDE and OWASP ASVS
- Automate testing using tools and integrating them such as vulnerability scanners, SAST, DAST, SCA and other relevant technologies including
- Collaborate with external penetration testing companies and clients to digest and review the risk of reports back to clients within their security requirements, provide recommendations to implement fixes to address identified vulnerabilities to internal stakeholders
- Stay up to date with the latest threats, vulnerabilities, red teaming, and penetration testing techniques through ongoing training and professional development
- Manage and mentor a team of juniors and interns.
Requirements:
7+ years of experience in penetration testing, with a strong focus on web applications, mobile and desktop apps, APIs, and infrastructure testing.
Willing to undergo background checks and security clearance.
Good level of Indi and English both spoken or written to a bilingual or at least Professional level, other languages at a bilingual/Professional level such as Arabic, Mandarin, French or German highly preferred.
Experience with cloud-based infrastructure and services - AWS, Azure, Google Cloud – containers, k8s and virtual machines.
Proven expertise in threat modelling, automation of testing, and advanced techniques (e.g., exploit development, reverse engineering)
OSCP or similar certification, GIAC Penetration Tester a plus
Strong knowledge of web application security frameworks, such as OWASP
Familiarity with mobile app security testing tools and techniques
Experience with desktop application security testing, including reverse engineering and exploit development
In-depth understanding of API security testing, including protocol analysis and exploitation.
Strong networking fundamentals, including TCP/IP, DNS, DHCP, BGP, etc.
Proficiency in scripting languages, such as Python, Ruby, PowerShell
Experience with agile development methodologies and collaboration tools like JIRA and their integrations
Excellent communication, problem-solving, and analytical skills
Nice to Have:
Familiarity with DevOps practices and security orchestration, automation, and monitoring (SOAM) tools
Knowledge of containerization technologies (e.g., Docker) and container-based vulnerability testing
Experience with OWASP ASVS and similar frameworks
Knowledge of machine learning models and associated security issues at the implementation and bypassing security restrictions.
Using API’s to automate work and systems along with reporting.
What We Offer:
Competitive salary and benefits package.
Opportunities for professional growth and development in a fast-paced and innovative environment
Collaborative team culture that values open communication, mutual respect, and teamwork
Access to cutting-edge security technologies and tools
Flexible work arrangements, including remote work options
If you are a motivated and experienced penetration tester looking for new challenges and opportunities, we encourage you to apply!
Join and help build a better, more efficient, safer and more secure world.
Penetration Tester
Posted 1 day ago
Job Viewed
Job Description
Skills Required:
Web Application PT -Must have
Application Security assessment- Must have
Mobile PT- Good to have
Cloud Must (knowledge + understanding of Azure and AWS)
Red Team Activities- Must
Active Directory PT -Must
Network & Infrastructure PT -Must have (protocols, Windows, Linux)
Firewall testing/auditing- Must
Citrix Pen testing- Good to have
Networking equipment- Must (routers, switchers, load balancers, how to attack them + common weaknesses)
Agile Process & Communication Good to have (it is essential that the candidate has good communication/interpersonal skills)
Certifications Completed or Optional OSCP, CPSA, CRT, CRTP, CEH (All good to have but not essential. I prefer practical knowledge than certifications)
Penetration Tester
Posted 16 days ago
Job Viewed
Job Description
Key Responsibilities:
- Perform network, web application, and mobile application penetration tests.
- Identify, analyze, and report on security vulnerabilities found during testing.
- Develop clear and concise reports detailing findings, risks, and remediation recommendations.
- Collaborate with development and operations teams to provide guidance on fixing identified vulnerabilities.
- Stay up-to-date with the latest penetration testing techniques, tools, and methodologies.
- Conduct security assessments and code reviews where necessary.
- Assist in developing and refining penetration testing strategies and procedures.
- Participate in post-test remediation verification.
- Maintain accurate documentation of all testing activities and results.
- Contribute to the continuous improvement of the information security program.
The ideal candidate will have a deep understanding of common attack vectors, exploitation techniques, and security best practices. Strong analytical and problem-solving skills are a must. Familiarity with scripting languages (e.g., Python, Bash) for automation is highly desirable. This role is based in Indore, Madhya Pradesh, IN , and requires occasional office presence for team meetings and collaborative sessions. If you are passionate about cybersecurity and excel at thinking like an attacker, this is an excellent opportunity to join a growing team and make a tangible difference. Our client is committed to professional development and provides opportunities to hone your skills in a challenging yet supportive environment.
Penetration Tester
Posted today
Job Viewed
Job Description
Web Application PT -Must have
Application Security assessment- Must have
Mobile PT- Good to have
Cloud Must (knowledge + understanding of Azure and AWS)
Red Team Activities- Must
Active Directory PT -Must
Network & Infrastructure PT -Must have (protocols, Windows, Linux)
Firewall testing/auditing- Must
Citrix Pen testing- Good to have
Networking equipment- Must (routers, switchers, load balancers, how to attack them + common weaknesses)
Agile Process & Communication Good to have (it is essential that the candidate has good communication/interpersonal skills)
Certifications Completed or Optional OSCP, CPSA, CRT, CRTP, CEH (All good to have but not essential. I prefer practical knowledge than certifications)
Penetration Tester
Posted today
Job Viewed
Job Description
As a Senior Penetration Tester, your primary role is to assess and enhance the security of our information systems, networks, and applications through comprehensive penetration testing and vulnerability assessments. You will work closely with our internal product teams to identify weaknesses in their systems and provide actionable recommendations for improvement. Your expertise will help safeguard sensitive data and protect our customers from potential cyber threats. Additionally, you will be responsible for coordinating penetration tests with third-party vendors when required.
Duties and Responsibilities
o Conduct penetration tests on a wide range of digital products, including networks, web, and mobile applications, to identify vulnerabilities and security weaknesses.
o Collaborate with internal product teams to understand their set-ups, goals, and constraints.
o Effectively communicate findings and solutions to technical and non-technical stakeholders.
o Prepare detailed and clear reports documenting findings, reproduce steps, and recommended remediation steps, ensuring the internal product teams understand the security implications.
o Work with cross-functional teams, including security engineers and developers to help them to implement security measures and resolve identified vulnerabilities.
o When your schedule is constrained, coordinate, and manage penetration tests with third-party vendors, ensuring high-quality and timely delivery.
o Contribute to the development and improvement of our testing methodologies, processes, and tools.
o Stay up to date with the latest threats, vulnerabilities, and exploits and develop new testing techniques as necessary.
o Conduct security tests based on products security requirements.
o
Authorities
o Authorized to conduct penetration tests and security tests on selected digital products.
o Authorized to make recommendations for remediation actions based on test results.
o Authorized to engage with internal product teams to discuss findings and recommendations.
o Authorized to coordinate and manage penetration tests with third-party vendors if needed.
Qualifications
o Bachelor’s degree in computer science/engineering, information security, or a related field.
o Proven experience in penetration testing, vulnerability assessment, and security testing with a minimum of 8 years in a similar role.
o Proven track record of conducting successful penetration tests for a variety of organizations and industries.
o Industry-recognized certifications such as Offensive Security Certified Professional (OSCP), GIAC Penetration Tester (GPEN) certifications, or similar qualifications are highly desirable.
o Demonstrated experience in vulnerability research (e.g., CVEs) is a plus.
o Experience in designing, developing, and executing customized penetration testing methodologies.
o Familiarity with various tools and frameworks used in penetration testing, such as Metasploit, Burp Suite, Nessus, Nmap etc.
o Strong knowledge of operating systems (Windows, Linux, and mobile platforms), databases, and web technologies.
o A deep understanding of common security protocols and technologies, including firewalls, intrusion detection/prevention systems, SSL/TLS.
o Programming skills and experience with languages such as Bash, Python, and PowerShell
o The ability to provide clear, comprehensive, and actionable reports on penetration test findings, including recommendations for remediation.
o Exceptional written and verbal communication skills to effectively convey technical information to both technical and non-technical stakeholders.
Be The First To Know
About the latest Penetration tester Jobs in India !
Penetration Tester
Posted 1 day ago
Job Viewed
Job Description
Location:
In Office, Ahmedabad, Gujarat, India (not remote)
Full-time
Salary: Up to ₹12.5L (1,250,000) INR per year for Senior/Lead
Must undergo background check and security clearance
Candidates must already have the right to work and live in India
About Asite
Asite’s vision is to connect people and help the world build better.
Asite’s platform enables organizations working on large capital projects to come together, plan, design, and build with seamless information sharing across the entire supply chain.
Asite SCM is our supply chain management solution, which helps owners and Tier-1 contractors to integrate and manage their extended supply chain for delivering on capital projects.
Asite PPM is our project portfolio management solution, which gives you and your extended supply chain shared visibility of your capital projects through one common data environment.
Together they enable organizations to build digital engineering teams that can deliver digital twins and just plain build better.
The company is headquartered in UK (London) and has regional offices in US (New York and Houston), UAE (Dubai), Australia (Sydney), China (Hong Kong) and India (Ahmedabad).
Job Summary:
We are seeking two Penetration Testers - Junior and Senior/Lead - to join our team of security professionals.
As a senior/lead penetration tester, you will be responsible for conducting comprehensive penetration testing on web applications, mobile and desktop apps, APIs, infrastructure, and other systems such as IoT devices.
You will utilize your expertise in threat modelling, automation of testing, and advanced techniques to identify vulnerabilities and provide actionable recommendations to improve the overall security posture of Asite SDLC and systems.
You will manage a small team that you also must mentor and guide in the best practices and help grow at both professional and managerial level.
You’ll report to the Information Security Officer ME & APAC based in India) and to the CISO (based in London)
You must have a passion for knowledge sharing and continuous learning.
You are willing to undergo background checks and Security Clearance.
Key Responsibilities:
Conduct thorough threat modelling, risk assessments and vulnerability scanning of web applications, mobile and desktop apps, APIs, infrastructure, and other systems
Identify and exploit vulnerabilities using various penetration testing tools, techniques, and methodologies – PTES, NIST 800-115, OWASP
Develop and maintain a comprehensive understanding of systems, including architecture, design patterns, and application logic
Design and implement effective threat models to identify potential entry points for attackers using STRIDE and OWASP ASVS
Automate testing using tools and integrating them such as vulnerability scanners, SAST, DAST, SCA and other relevant technologies including
Collaborate with external penetration testing companies and clients to digest and review the risk of reports back to clients within their security requirements, provide recommendations to implement fixes to address identified vulnerabilities to internal stakeholders
Stay up to date with the latest threats, vulnerabilities, red teaming, and penetration testing techniques through ongoing training and professional development
Manage and mentor a team of juniors and interns.
Requirements:
7+ years of experience in penetration testing, with a strong focus on web applications, mobile and desktop apps, APIs, and infrastructure testing.
Willing to undergo background checks and security clearance.
Good level of Indi and English both spoken or written to a bilingual or at least Professional level, other languages at a bilingual/Professional level such as Arabic, Mandarin, French or German highly preferred.
Experience with cloud-based infrastructure and services - AWS, Azure, Google Cloud – containers, k8s and virtual machines.
Proven expertise in threat modelling, automation of testing, and advanced techniques (e.g., exploit development, reverse engineering)
OSCP or similar certification, GIAC Penetration Tester a plus
Strong knowledge of web application security frameworks, such as OWASP
Familiarity with mobile app security testing tools and techniques
Experience with desktop application security testing, including reverse engineering and exploit development
In-depth understanding of API security testing, including protocol analysis and exploitation.
Strong networking fundamentals, including TCP/IP, DNS, DHCP, BGP, etc.
Proficiency in scripting languages, such as Python, Ruby, PowerShell
Experience with agile development methodologies and collaboration tools like JIRA and their integrations
Excellent communication, problem-solving, and analytical skills
Nice to Have:
Familiarity with DevOps practices and security orchestration, automation, and monitoring (SOAM) tools
Knowledge of containerization technologies (e.g., Docker) and container-based vulnerability testing
Experience with OWASP ASVS and similar frameworks
Knowledge of machine learning models and associated security issues at the implementation and bypassing security restrictions.
Using API’s to automate work and systems along with reporting.
What We Offer:
Competitive salary and benefits package.
Opportunities for professional growth and development in a fast-paced and innovative environment
Collaborative team culture that values open communication, mutual respect, and teamwork
Access to cutting-edge security technologies and tools
Flexible work arrangements, including remote work options
If you are a motivated and experienced penetration tester looking for new challenges and opportunities, we encourage you to apply!
Join and help build a better, more efficient, safer and more secure world.