OSCP certified AND Penetration tester at HighQ-labs · Bengaluru (Bangalore) · 5 - 7 years · ₹15L - ₹20L / yr · Profitable · Posted 15 Jul 2025

Penetration Testing Expert Requirements and Qualification:
Previous working experience as a Penetration Testing Expert for 5 - 7 year
BE in Computer Information Systems, Management Information Systems, or similar relevant field
In-depth knowledge of application development processes and at least one programing or scripting language (e.g., Java, Scala, C#, Ruby, Perl, Python, PowerShell)
Must know about standard Industry security Practices (OWASP, SANS, etc), Knowledgeable about industry Security guidelines and compliance such as ISO27001, SOC2, HIPPA etc.
Hands on experience with testing frameworks such as the PTES and OWASP.
Applicable knowledge of Windows client/server, Unix/Linux systems, Mac OS X, VMware/Xen, and cloud technologies such as AWS, Azure, or Google Cloud
Critical thinker and problem solver
Excellent organizational and time management skills
Penetration Tester Role:
The Penetration Tester, will provide broad and in depth knowledge to conduct offensive cyber operations across the organization globally. In this role, you will conduct offensive security operations to emulate adversary tactics and procedures to test preventative, detective and response controls across the global technology landscape. You will use your expertise to help influence technology decisions and work as part of a team to create consistent approaches to the offensive security processes and techniques.
Penetration Testing Duties and Responsibilities:
Operate a hands-on role involving penetration testing and vulnerability assessment activities of complex applications, operating systems, wired, wireless networks, and mobile applications/devices, Cloud (Azure, AWS, Google Etc) apps and software’s.
Set up environment and maintain required tools needed for the team.
Lead and manage Penetration Testing team and Supporting vendors to get qualitative deliveries to our customer.
Develop and maintain security testing plans
Able to automate penetration and other security testing on networks, systems and applications.
Develop meaningful metrics to reflect the true posture of the environment allowing the organization to make educated decisions based on risk.
Produce actionable, threat-based, reports on security testing results
Act as a source of direction, training, and guidance for less experienced staff
Consult with application developers, systems administrators, and management to demonstrate security testing results, explain the threat presented by the results, and consult on remediation
Communicate security issues to a wide variety of internal and external “customers” to include technical teams, executives, risk groups, vendors and regulators
Deliver the annual penetration testing schedule and conducting awareness campaigns to ensure proper budgeting by business lines for annual tests.
Foster and maintain relationships with key stakeholders and business partners
Certificates:
Must Have
Offensive Security Certified Professional (OSCP)
Good to have
CREST Registered Penetration Tester (CRT)
Certified Ethical Hacker (CEH) Certification
GIAC Certified Penetration Tester (GPEN)

About HighQ-labs
About
Company social profiles
Similar jobs (10)
We are looking for a Penetration Tester to find and fix security weaknesses in our systems.
Responsibilities
- Run web, mobile, API and network penetration tests
- Write clear reports with fix guidance
- Retest after fixes are applied
- Keep up with new attack techniques
Requirements
- 1+ years of VAPT experience
- Strong OWASP and Burp Suite skills
- OSCP or CEH certification is a plus
A BIT ABOUT US
Appknox is one of the top Mobile Application security companies recognized by Gartner and G2. A profitable B2B SaaS startup headquartered in Singapore & working from Bengaluru.
The primary goal of Appknox is to help businesses and mobile developers secure their mobile applications with a focus on delivery speed and high-quality security audits.
Appknox has helped secure mobile apps at Fortune 500 companies with major brands spread across regions like India, South-East Asia, Middle-East, US, and expanding rapidly. We have secured 300+ Enterprises globally.
We are a 65+ incredibly passionate team working to make an impact and helping some of the biggest companies globally. We work in a highly collaborative, very fast-paced work environment. If you have what it takes to be part of the team, we are excited and let’s speak further.
The Opportunity
To join the security team engaging with multiple clients, helping them with end to end security audits, also research about new topics and vulnerabilities to be added to the scanner, present it in conferences.
What An Ideal Candidate Would Look Like:
- Skills - Application Penetration Testing (Web, iOS and Android), experience with IoT testing, source code audits.
- Technology Stack: AWS, GCP, Objective C, Java, Python
- Responsibilities: Engage with clients for scoping call, perform security audits, remediation call with clients to patch the issues, research on new technologies/vulnerabilities
Minimum Requirements
- 2-4+ years of experience in application security and vulnerability research
- Strong foundation in mobile app security - Android or Ios
- Proven track record of discovering and disclosing CVEs in mobile platforms or popular applications (provide - github/bug bounty profiles)
- Strong understanding of exploit mitigations and proven ability to bypass them
- Should be able to architect automated detection logic for new vulnerabilities and integrate them into our security products
- Develop AI-driven agents to automate dynamic analysis
- Should be able to Leverage AI/LLMs to augment Pentesting efforts
- Ability to work independently in a fast-paced environment, balancing deep research with practical deliverables
Good to have Requirements
- Understanding of AI/ML security risks
Responsibilities
- Security assessment of web/mobile applications on various platforms
- Focusing on Mobile Application Security Research for new vulnerabilities
- Static and Dynamic Code Analysis
- Develop and interpret security standards and guides
- Automation of exploit development
- Understand and explain the results with impact on business and compliance status
- Continuously learning and training on latest tools and technique
Work Expectations
Within 1 month
Training on processes, security workflows and develop understanding on internal tools.
Within 3 months
Actively contributing in exploit development and automation of it with the team.
Within 6 months
Expected to achieve Subject Matter Expert status on our core security products. We expect you to validate your findings against real-world conditions, with a strong emphasis on translating internal discoveries into actionable bug bounty submissions and earned CVEs to benchmark your impact against the external security community.
Within 1 Year
By the end of your first year, you will be expected to produce and submit a piece of novel, peer-reviewed security research. This deliverable must be of a quality suitable for top-tier industry conferences.
Personality traits we really admire
- A confident and dynamic working persona, which can bring fun to the team, and a sense of humour, is an added advantage.
- Great attitude to ask questions, learn and suggest process improvements.
- Has attention to details and helps identify edge cases.
- Highly motivated and coming up with fresh ideas and perspectives to help us move towards our goals faster.
- Follow timelines and absolute commitment to deadlines.
Interview Process - would be team specific
- Round 1- CTF round
- Round 2 -Profile Evaluation; HR
- Round 3 -Technical Interview with security team members
- Round 4 -Technical Interview with the Hiring Manager
- Round 5 -Technical round with CTO
- Round 6 -HR Round
Compensation
- As per Industry Standards
Why Join Us
- Freedom & Responsibility: If you are a person who enjoys challenging work & pushing your boundaries, then this is the right place for you. We appreciate new ideas & ownership as well as flexibility with working hours.
- Great Salary & Equity: We keep up with the market standards & provide pay packages considering updated standards. Also as Appknox continues to grow, you’ll have a great opportunity to earn more & grow with us. Moreover, we also provide equity options for our top performers.
- Holistic Growth: We foster a culture of continuous learning and take a much more holistic approach to train and develop our assets: the employees. We shall also support you all on that journey of yours.
- Transparency: Being a part of a start-up is an amazing experience, one of the reasons being open communication & transparency at multiple levels. Working with Appknox will give you the opportunity to experience it all first-hand.
Hi Folks, we are currently Hiring for Security Engineer.
Gemini said
Hiring: Security Engineer
Company : Pentabay Softwares
Location : Anna salai, Mount Road
Mode: Fulltime
Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.
The Mission
You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.
Key Responsibilities
Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.
Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.
DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.
Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.
Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.
What You Bring
Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).
Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).
Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.
Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).
Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.
Auditing space like ISO27001 , ISO9001 prefered
Why Pentabay?
At Pentabay, we offer more than just a job; we offer a security-first engineering culture.
Growth: A dedicated learning budget for certifications and conferences.
Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.
Send resumes to : sandhiya.m at pentabay.com
Cybersecurity Engineer – AI Training Project
About the Opportunity
We’re looking for experienced Cybersecurity Engineers to contribute technical expertise to a customer project focused on improving the capabilities of next-generation AI systems.
In this role, you’ll use your real-world experience in cybersecurity, software engineering, vulnerability assessment, and secure development to create high-quality technical inputs that help AI systems better understand, debug, secure, and reason about complex software.
What You’ll Do
- Analyze, debug, and resolve software bugs, vulnerabilities, and security issues across complex codebases.
- Review source code and identify potential security weaknesses, vulnerabilities, and attack vectors.
- Perform security assessments, vulnerability assessments, penetration testing, and codebase audits.
- Develop and modify software using languages such as Python, Java, Rust, Go, C++, or TypeScript.
- Implement new features and fix existing functionality while maintaining strong security and engineering standards.
- Refactor legacy code to improve security, maintainability, reliability, and performance.
- Work on backend systems and help optimize applications for scalability, performance, and security.
- Analyze real-world security scenarios and translate your expertise into high-quality technical examples and problem-solving tasks.
- Document technical findings, vulnerabilities, debugging approaches, and recommended solutions.
- Provide domain expertise that helps improve how AI systems reason about software engineering and cybersecurity problems.
What We’re Looking For
- Strong professional experience in Cybersecurity / Application Security / Product Security / DevSecOps / Penetration Testing / Vulnerability Management.
- Strong programming experience in one or more of:
- Python
- Java
- Rust
- Go
- C++
- TypeScript
- Proven experience with debugging, troubleshooting, and fixing complex software issues.
- Hands-on experience with penetration testing, vulnerability assessment, security auditing, or application security.
- Understanding of secure software development practices and modern security threats.
- Strong knowledge of data structures, algorithms, software architecture, and code quality.
- Ability to review unfamiliar codebases and quickly understand how systems work.
- Strong written communication and the ability to explain complex technical findings clearly.
Nice to Have
- Experience with OWASP, API security, cloud security, DevSecOps, or threat modeling.
- Experience performing security assessments on production applications or enterprise systems.
- Experience with tools such as Burp Suite, Metasploit, Nmap, Wireshark, SAST/DAST tools, or vulnerability scanners.
- Contributions to open-source security or software projects.
- Experience working with AI/ML systems, LLMs, data annotation, or AI training projects.
- Relevant security certifications such as OSCP, OSWE, CEH, CISSP, Security+, or equivalent practical experience.
Engagement
- Role: Cybersecurity Engineer
- Work: Remote(Contract)
- Experience: Mid-level to Senior
- Programming: Required
- Cybersecurity expertise: Required
Why Join?
This is an opportunity to apply your existing cybersecurity expertise to an emerging area of technology. Your practical experience debugging software, identifying vulnerabilities, securing applications, and solving complex engineering problems will directly contribute to improving the capabilities of next-generation AI systems.
If you enjoy breaking down complex technical problems, finding vulnerabilities, fixing software, and thinking deeply about how systems work, this project could be a strong fit.
Responsibilities
- Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
- Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
- Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
- Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
- Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
- Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
- Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
- Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
- Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
- Provide input into policies and standards related to application and cloud security controls.
Qualifications and Education Requirements
- Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
- 5-7 years of relevant experience in application security and/or vulnerability management.
- Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
- Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
- Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
- Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
- Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
- Excellent documentation, communication, and stakeholder engagement skills.
Desired Skills
- Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
- Experience using the ServiceNow platform for vulnerability or incident tracking.
- Proficiency in Azure cloud and Azure DevOps environments.
- Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.
Cyber Security Expert
We are seeking a highly skilled Cyber Security Expert with strong expertise in AI-driven
security tools and ethical hacking techniques. The ideal candidate will safeguard our digital
infrastructure, proactively identify vulnerabilities, and design intelligent defense mechanisms
against evolving cyber threats.
Key Responsibilities
• Threat Analysis: Identify, assess, and mitigate potential risks across systems and
networks.
• AI Security Tools: Deploy and manage AI-based solutions for intrusion detection,
anomaly monitoring, and predictive threat modelling.
• Ethical Hacking: Conduct penetration testing, simulate cyber-attacks, and recommend
remediation strategies.
• Incident Response: Lead investigations, contain breaches, and implement recovery
measures.
• Compliance & Governance: Ensure adherence to data protection laws, industry
standards, and organizational policies.
• Training & Awareness: Educate employees on best practices and emerging threats.
Required Skills & Qualifications
• Proven hands-on experience with AI-powered security platforms (e.g., SIEM, SOAR,
ML-based anomaly detection).
• Strong knowledge of ethical hacking tools (Metasploit, Burp Suite, Kali Linux, etc.).
• Expertise in network security, firewalls, IDS/IPS, and endpoint protection.
• Familiarity with cloud security (AWS, cloud platform).
• Proficiency in scripting languages (Python, Bash, PowerShell) for automation.
• Solid understanding of cryptography, authentication protocols, and secure coding
practices.
- Develop python-based automation for large data sets data analysis for vulnerability management reporting.
- Leverage machine learning in the process as required.
- Develop Prompts to automate test data extraction process from databases.
- Provide technical expertise through a hands-on approach to teams and projects.
- Experience with one or more general purpose programming languages including but not limited to: Java, Python, R or equivalent
- Experience and knowledge in designing, building, and deploying multi layered application Infrastructure involving On-premises & AWS Cloud platform using services BedRock LLM models.
- Handle design, definition, planning and development.
- 100% adherence to architectural and development best practices including the use of standard architectures, proper use of code management, document design and design artifacts and conduct design/code reviews.
- Create optimization plans to innovate, shift-left, and mitigate gaps.
- Apply cloud concepts and capabilities to deliver testing for cloud-hosted apps.
- Report succinct testing goals and results to the leadership.
- Train and educate various teams on SV ideas and expectations.
- Expand responsibilities to drive test data, test environment, and service virtualization strategies.
About the team
SecurITe’s mission is to build an Agentic‑AI driven security platform that protects critical infrastructure from modern cyber threats. Our focus is on delivering highly performant, resilient, and intelligent network security systems that help defenders stay ahead of adversaries.
About the Role
We’re looking for a seasoned Senior Quality Engineer to provide technical leadership and architectural oversight for our next‑generation cybersecurity AI platform. In this high-impact role, you will define the technical strategy for quality assurance, ensuring our agentic AI transforms cyber defense with unparalleled reliability.
You will be responsible for the end-to-end quality lifecycle, from architectural reviews to the deployment of scalable automation frameworks. Beyond technical execution, you will serve as a mentor to junior team members, fostering a culture of technical excellence and driving the strategy that ensures our solutions meet the rigorous demands of critical infrastructure protection.
What You’ll Do
● Defining and driving comprehensive QA strategies and roadmaps for the cybersecurity platform.
● Designing, developing, and executing test plans, test cases, and automated scripts to ensure software quality.
● Performing functional, regression, performance, scalability and security testing to identify bugs or defects.
● Collaborating with developers, product managers, and other stakeholders to understand product requirements and testing needs.
● Identifying, documenting, and tracking software defects, ensuring clear communication of issues and their resolutions.
● Leading deep-dive root-cause analysis for critical system defects and security vulnerabilities.
● Conducting thorough reviews of product specifications and software design to identify potential areas of concern before testing.
● Architecting and designing complex, scalable test automation frameworks to optimize CI/CD velocity.
● Ensuring the software meets customer and business requirements by validating the functionality and performance.
● Assisting in continuously improving QA processes, tools, and best practices to enhance software testing efficiency and effectiveness.
● Supporting user acceptance testing (UAT) and assisting clients with product validation.
● Mentoring junior and mid-level engineers, providing technical guidance and conducting architectural reviews.
Required Experience
● A Bachelor’s degree in Computer Science, Information Technology, Computer Engineering, or a related field.
● 8-10 years of proven experience in quality engineering, specifically within network cybersecurity, Identity Providers, or AI-integrated platforms.
● Expertise in manual and automated testing.
● Deep domain expertise in complex system validation and advanced automation practices at scale.
● Proficiency in programming languages like Python to build and run automated test scripts.
● "Strong knowledge of software testing methodologies, performance testing tools (e.g., JMeter, k6), and security traffic generation/simulation tools (e.g., Ixia BreakingPoint, Scapy, or Snort/Suricata traffic generators)."
● Understanding of continuous integration/continuous deployment (CI/CD) pipelines and version control systems like Git.
● Strong communication skills for documenting test results and interacting with cross-functional teams.
● Excellent analytical skills, attention to detail, and problem-solving ability.
● Ability to work independently as well as collaboratively in a team environment.
● A curious mindset with a willingness to quickly learn new technologies and testing tools.
Required Skills & Qualifications
● Familiarity with cloud-based testing environments (GCP, AWS, Azure).
● Experience with cybersecurity products or cloud services or IDP or Web UI
The Mindset
● Problem Solver: You thrive on complex, ambiguous challenges and engineer elegant solutions.
● Ownership‑Driven: You take initiative, move fast, and deliver outcomes without hand‑holding.
● Continuous Learner: You stay ahead of the curve in AI, ML, and emerging technologies.
● Startup DNA: You excel in fast‑moving environments where priorities evolve and impact is immediate.
We are looking for a Cybersecurity Engineer to protect our systems, applications and data. You will find vulnerabilities, monitor threats and strengthen our overall security posture.
Responsibilities
- Run vulnerability assessments and penetration tests (VAPT) on web apps, APIs and networks
- Monitor and respond to security events using SIEM tools as part of SOC operations
- Test application security using Burp Suite and similar tools
- Support ISO 27001 compliance, audits and security policies
- Harden network infrastructure, firewalls and access controls
- Document findings and track fixes with engineering teams
Requirements
- 1+ years of experience in VAPT, SOC or security engineering
- Hands-on experience with Burp Suite and SIEM tools
- Knowledge of the OWASP Top 10 and network security fundamentals
- Exposure to ISO 27001 or similar frameworks
- Certifications such as CEH, OSCP or CompTIA Security+ are a plus

Senior Automation Testing Engineer
Location: Bengaluru / Gurugram – Onsite
Experience: 5–11 Years
Employment Type: Full-Time
Key Responsibilities
- Develop and maintain automation test frameworks and scripts.
- Perform both manual and automation testing, including exploratory, functional, regression, and bug verification.
- Develop test cases and contribute to test planning, estimation, and Agile ceremonies.
- Perform non-functional testing for accuracy, reliability, and performance.
- Drive QA process and automation improvements.
Required Skills
- BE/B.Tech/ME/M.Tech in CS/ECE/EE or related field.
- 5–11 years of software testing experience.
- Strong hands-on experience with Python/Java, Selenium, Cucumber, and PyTest.
- Good knowledge of SDLC, testing methodologies, defect lifecycle, and risk assessment.
- Experience with version control and bug-tracking tools.
Good to Have: Linux, Qt/QML, Squish, ISTQB/CSM/PSM, and regulatory/compliance standards.





