Cybersecurity Operations
Tester, Tier-1
Location
Mumbai, India
Work type
Remote
Employment
Full Time
Experience
3-5 years
Compensation
₹1L - ₹2L per month
Posted
18h ago
Summary and responsibilities
Role overview
Summary
This role involves performing penetration tests on customer networks and applications, utilizing both black-box and grey-box approaches. The individual will be responsible for logging activity, collecting evidence, setting up lab environments, and contributing to customer reports.
Responsibilities
Perform penetration tests from both the outside and the inside of a customer network
Assess customer applications using both black-box and grey-box approaches
Log all activity, collect tool output, and capture evidence
Secure work product to prevent accidental disclosure
Setup lab environments for reverse engineering and attack POC
Provide Daily Status Reports to team leads
Contribute to customer reports
Required Skills
3-5 years of experience in performing penetration tests against mobile, web, and enterprise applications including API
Experience testing traditional web applications such as PHP, ASPX, and JSP as well as more modern applications such as those based on NodeJS
Experience testing a variety of different API including REST and websocket API using a variety of different data structures such as XML and JSON
Experience using tools such as testssl, dirbuster, Burpsuite and SoapUI for testing web applications and API
Experience using tools such as class dump, clutch, gdb, cycript, apk tool, sqlite manager, drozer, and frida for testing mobile applications
Experience manually executing attacks such as XSS, CSRF, SQL Injection, Command Injection, XXEi, LFI, SSRF, etc.
Experience with the OWASP testing guide
Intermediate knowledge of Windows and Linux
Good knowledge of programming languages such as JavaScript, PHP, Java, python, or C
Can write concise and meaningful reports to both upper management and technical level audiences
Preferred Skills
Experience debugging applications with tools such as gdb, IDA, Ghirdra, and valgrind
Experience fuzzing application input via the network and file system using tools such spike
Experience with automated code review using tools such as cppcheck and GoSec
Experience with manually reviewing code written in C, go, or other similarly compiled language for flaws
Experience with the OWASP mobile testing guide and Software Assurance Maturity Model
Good knowledge of TCP/IP and other application and network level protocols
Ability to provide suggestions to remediate vulnerabilities
GWAPT or OSWA certification
Preferred Skills
Ability to self-manage including planning, providing status updates and metrics
Can communicate well (written and spoken)
Can work alone or in a team
Good organization skills
Good time management
Responds well to criticism and encouragement from co-workers and customers
Updated 12h ago
Candidate fit
Skills and qualifications
Additional skills
Experience
3-5 years
Certifications
How this role is positioned
Role classification
Job domains
Industries
Employment
Full Time
Contract duration
Permanent
Hiring type
Direct
Global hiring
Location specific
Offer details
Compensation and benefits
Compensation
₹1L - ₹2L per month
Location, schedule, and role shape
Work setup
Work conditions
Bandwidth profile
Context on the employer
Company snapshot
Company
Hellfire Security
Team size
Growing team
Location
Mumbai, India
Popular Domains
Explore opportunities across specialized functional areas.
Trending Industries
Discover roles in the world's most innovative sectors.
Cybersecurity Operations
Mumbai, India • Full Time