Penetration Tester at Creating beautiful automation's in software and hardware ind · Remote only · 2 - 6 years · ₹4L - ₹8L / yr · Remote only · Posted 16 Feb 2022

Penetration Tester
at Creating beautiful automation's in software and hardware ind
Key Responsibility Areas:
- Operate a hands-on role involving penetration testing and vulnerability assessment activities of complex Web applications, operating systems, wired and wireless networks, and mobile applications/devices
- Delivering targeted and intelligence led security penetration testing through a robust testing methodology and process
- Craft and develop scripts, frameworks, tools, and the methods required for facilitating and executing sophisticated charges, emulating malicious actor behavior sought at avoiding detection
- Conduct security assessments on a wide variety of technologies and implementations
- Develop and maintain security testing plans
- Maintain and evolve a mature set of security penetration testing and internal Red Team processes covering all areas of technology
- Automate penetration and other security testing on networks, systems and applications
- Develop meaningful metrics to reflect the true posture of the environment allowing the organization to make educated decisions based on risk
- Produce actionable, threat-based, reports on security testing results
- Act as a source of direction, training, and guidance for less experienced staff

Similar jobs (4)
We are looking for a Penetration Tester to find and fix security weaknesses in our systems.
Responsibilities
- Run web, mobile, API and network penetration tests
- Write clear reports with fix guidance
- Retest after fixes are applied
- Keep up with new attack techniques
Requirements
- 1+ years of VAPT experience
- Strong OWASP and Burp Suite skills
- OSCP or CEH certification is a plus
We are looking for a Cybersecurity Engineer to protect our systems, applications and data. You will find vulnerabilities, monitor threats and strengthen our overall security posture.
Responsibilities
- Run vulnerability assessments and penetration tests (VAPT) on web apps, APIs and networks
- Monitor and respond to security events using SIEM tools as part of SOC operations
- Test application security using Burp Suite and similar tools
- Support ISO 27001 compliance, audits and security policies
- Harden network infrastructure, firewalls and access controls
- Document findings and track fixes with engineering teams
Requirements
- 1+ years of experience in VAPT, SOC or security engineering
- Hands-on experience with Burp Suite and SIEM tools
- Knowledge of the OWASP Top 10 and network security fundamentals
- Exposure to ISO 27001 or similar frameworks
- Certifications such as CEH, OSCP or CompTIA Security+ are a plus
Responsibilities
- Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
- Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
- Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
- Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
- Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
- Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
- Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
- Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
- Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
- Provide input into policies and standards related to application and cloud security controls.
Qualifications and Education Requirements
- Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
- 5-7 years of relevant experience in application security and/or vulnerability management.
- Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
- Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
- Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
- Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
- Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
- Excellent documentation, communication, and stakeholder engagement skills.
Desired Skills
- Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
- Experience using the ServiceNow platform for vulnerability or incident tracking.
- Proficiency in Azure cloud and Azure DevOps environments.
- Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.
A BIT ABOUT US
Appknox is one of the top Mobile Application security companies recognized by Gartner and G2. A profitable B2B SaaS startup headquartered in Singapore & working from Bengaluru.
The primary goal of Appknox is to help businesses and mobile developers secure their mobile applications with a focus on delivery speed and high-quality security audits.
Appknox has helped secure mobile apps at Fortune 500 companies with major brands spread across regions like India, South-East Asia, Middle-East, US, and expanding rapidly. We have secured 300+ Enterprises globally.
We are a 65+ incredibly passionate team working to make an impact and helping some of the biggest companies globally. We work in a highly collaborative, very fast-paced work environment. If you have what it takes to be part of the team, we are excited and let’s speak further.
The Opportunity
To join the security team engaging with multiple clients, helping them with end to end security audits, also research about new topics and vulnerabilities to be added to the scanner, present it in conferences.
What An Ideal Candidate Would Look Like:
- Skills - Application Penetration Testing (Web, iOS and Android), experience with IoT testing, source code audits.
- Technology Stack: AWS, GCP, Objective C, Java, Python
- Responsibilities: Engage with clients for scoping call, perform security audits, remediation call with clients to patch the issues, research on new technologies/vulnerabilities
Minimum Requirements
- 2-4+ years of experience in application security and vulnerability research
- Strong foundation in mobile app security - Android or Ios
- Proven track record of discovering and disclosing CVEs in mobile platforms or popular applications (provide - github/bug bounty profiles)
- Strong understanding of exploit mitigations and proven ability to bypass them
- Should be able to architect automated detection logic for new vulnerabilities and integrate them into our security products
- Develop AI-driven agents to automate dynamic analysis
- Should be able to Leverage AI/LLMs to augment Pentesting efforts
- Ability to work independently in a fast-paced environment, balancing deep research with practical deliverables
Good to have Requirements
- Understanding of AI/ML security risks
Responsibilities
- Security assessment of web/mobile applications on various platforms
- Focusing on Mobile Application Security Research for new vulnerabilities
- Static and Dynamic Code Analysis
- Develop and interpret security standards and guides
- Automation of exploit development
- Understand and explain the results with impact on business and compliance status
- Continuously learning and training on latest tools and technique
Work Expectations
Within 1 month
Training on processes, security workflows and develop understanding on internal tools.
Within 3 months
Actively contributing in exploit development and automation of it with the team.
Within 6 months
Expected to achieve Subject Matter Expert status on our core security products. We expect you to validate your findings against real-world conditions, with a strong emphasis on translating internal discoveries into actionable bug bounty submissions and earned CVEs to benchmark your impact against the external security community.
Within 1 Year
By the end of your first year, you will be expected to produce and submit a piece of novel, peer-reviewed security research. This deliverable must be of a quality suitable for top-tier industry conferences.
Personality traits we really admire
- A confident and dynamic working persona, which can bring fun to the team, and a sense of humour, is an added advantage.
- Great attitude to ask questions, learn and suggest process improvements.
- Has attention to details and helps identify edge cases.
- Highly motivated and coming up with fresh ideas and perspectives to help us move towards our goals faster.
- Follow timelines and absolute commitment to deadlines.
Interview Process - would be team specific
- Round 1- CTF round
- Round 2 -Profile Evaluation; HR
- Round 3 -Technical Interview with security team members
- Round 4 -Technical Interview with the Hiring Manager
- Round 5 -Technical round with CTO
- Round 6 -HR Round
Compensation
- As per Industry Standards
Why Join Us
- Freedom & Responsibility: If you are a person who enjoys challenging work & pushing your boundaries, then this is the right place for you. We appreciate new ideas & ownership as well as flexibility with working hours.
- Great Salary & Equity: We keep up with the market standards & provide pay packages considering updated standards. Also as Appknox continues to grow, you’ll have a great opportunity to earn more & grow with us. Moreover, we also provide equity options for our top performers.
- Holistic Growth: We foster a culture of continuous learning and take a much more holistic approach to train and develop our assets: the employees. We shall also support you all on that journey of yours.
- Transparency: Being a part of a start-up is an amazing experience, one of the reasons being open communication & transparency at multiple levels. Working with Appknox will give you the opportunity to experience it all first-hand.







