Back to jobs
Regional hiringpublishedExternal employer
HSHellfire Security
Hellfire SecurityCybersecurity

Cybersecurity Operations

Tester, Tier-1

Location

Mumbai, India

Work type

Remote

Employment

Full Time

Experience

3-5 years

Compensation

₹1L - ₹2L per month

Posted

18h ago

Summary and responsibilities

Role overview

Summary

This role involves performing penetration tests on customer networks and applications, utilizing both black-box and grey-box approaches. The individual will be responsible for logging activity, collecting evidence, setting up lab environments, and contributing to customer reports.

Responsibilities

  • Perform penetration tests from both the outside and the inside of a customer network

  • Assess customer applications using both black-box and grey-box approaches

  • Log all activity, collect tool output, and capture evidence

  • Secure work product to prevent accidental disclosure

  • Setup lab environments for reverse engineering and attack POC

  • Provide Daily Status Reports to team leads

  • Contribute to customer reports

Required Skills

  • 3-5 years of experience in performing penetration tests against mobile, web, and enterprise applications including API

  • Experience testing traditional web applications such as PHP, ASPX, and JSP as well as more modern applications such as those based on NodeJS

  • Experience testing a variety of different API including REST and websocket API using a variety of different data structures such as XML and JSON

  • Experience using tools such as testssl, dirbuster, Burpsuite and SoapUI for testing web applications and API

  • Experience using tools such as class dump, clutch, gdb, cycript, apk tool, sqlite manager, drozer, and frida for testing mobile applications

  • Experience manually executing attacks such as XSS, CSRF, SQL Injection, Command Injection, XXEi, LFI, SSRF, etc.

  • Experience with the OWASP testing guide

  • Intermediate knowledge of Windows and Linux

  • Good knowledge of programming languages such as JavaScript, PHP, Java, python, or C

  • Can write concise and meaningful reports to both upper management and technical level audiences

Preferred Skills

  • Experience debugging applications with tools such as gdb, IDA, Ghirdra, and valgrind

  • Experience fuzzing application input via the network and file system using tools such spike

  • Experience with automated code review using tools such as cppcheck and GoSec

  • Experience with manually reviewing code written in C, go, or other similarly compiled language for flaws

  • Experience with the OWASP mobile testing guide and Software Assurance Maturity Model

  • Good knowledge of TCP/IP and other application and network level protocols

  • Ability to provide suggestions to remediate vulnerabilities

  • GWAPT or OSWA certification

Preferred Skills

  • Ability to self-manage including planning, providing status updates and metrics

  • Can communicate well (written and spoken)

  • Can work alone or in a team

  • Good organization skills

  • Good time management

  • Responds well to criticism and encouragement from co-workers and customers

Updated 12h ago

Candidate fit

Skills and qualifications

Additional skills

Penetration Testing • 1+ yrs
Mobile Application Testing • 1+ yrs
Web Application Testing • 1+ yrs
API Testing • 1+ yrs
XSS • 1+ yrs
CSRF • 1+ yrs
SQL Injection • 1+ yrs
Command Injection • 1+ yrs
XXEi • 1+ yrs
LFI • 1+ yrs
SSRF • 1+ yrs
Windows • 1+ yrs
Linux • 1+ yrs
JavaScript • 1+ yrs
PHP • 1+ yrs
Java • 1+ yrs
Python • 1+ yrs
C • 1+ yrs
Debugging • 1+ yrs
Fuzzing • 1+ yrs
Automated Code Review • 1+ yrs
Manual Code Review • 1+ yrs
TCP/IP • 1+ yrs
Network Protocols • 1+ yrs
Vulnerability Remediation • 1+ yrs
testssl • 1+ yrs
dirbuster • 1+ yrs
Burpsuite • 1+ yrs
SoapUI • 1+ yrs
class dump • 1+ yrs
clutch • 1+ yrs
gdb • 1+ yrs
cycript • 1+ yrs
apk tool • 1+ yrs
sqlite manager • 1+ yrs
drozer • 1+ yrs
frida • 1+ yrs
IDA • 1+ yrs
Ghirdra • 1+ yrs
valgrind • 1+ yrs
spike • 1+ yrs
cppcheck • 1+ yrs
GoSec • 1+ yrs
Black-box testing • 1+ yrs
Grey-box testing • 1+ yrs
OWASP testing guide • 1+ yrs
OWASP mobile testing guide • 1+ yrs
Software Assurance Maturity Model • 1+ yrs
Reporting • 1+ yrs
Communication • 1+ yrs
Self-management • 1+ yrs
Planning • 1+ yrs
Organization skills • 1+ yrs
Time management • 1+ yrs
Responsiveness to criticism • 1+ yrs

Experience

3-5 years

Certifications

GWAPT • Required
OSWA certification • Required

How this role is positioned

Role classification

Job domains

Other
Operations

Industries

Technology & IT
Cybersecurity

Employment

Full Time

Contract duration

Permanent

Hiring type

Direct

Global hiring

Location specific

Offer details

Compensation and benefits

Compensation

₹1L - ₹2L per month

VisibilityShared on listing
CurrencyINR
PeriodMonthly

Location, schedule, and role shape

Work setup

Work conditions

Primary locationMumbai, India
Work typeRemote
Global hiringNo

Bandwidth profile

peopleMedium6/10
physicalLow1/10
cognitiveHigh8/10
executionHigh8/10
creativityHigh8/10
uncertaintyHigh8/10
communicationHigh8/10

Context on the employer

Company snapshot

Company

Hellfire Security

Team size

Growing team

Location

Mumbai, India

Cybersecurity Operations

Mumbai, IndiaFull Time