Job Summary
Key Responsibilities
3.3.1 Senior Penetration Tester
- Desired Outcomes: Proactively identify and exploit vulnerabilities in applications, infrastructure, and human processes through ethical hacking. Provide clear, actionable remediation guidance and contribute to a stronger security posture.
- Key Responsibilities:
- Conduct advanced penetration tests on web applications, mobile applications, APIs, AI/ML systems, and infrastructure.
- Perform red teaming exercises to simulate real-world attacks.
- Integrate security testing into DevSecOps CI/CD pipelines.
- Provide expert recommendations for vulnerability remediation.
- Generate comprehensive penetration test reports.
- Support during ongoing security incidents
- Scope/Frequency:
- Tier 1 – High-Frequency Applications
- Count: 9 applications
- Frequency: Once every 2 months
- Cycles per year per app: 6
- Total annual tests: 9 × 6 = 54 penetration tests/year
- These applications typically involve:
- High external exposure
- Sensitive data
- Frequent releases or configuration changes
- Regulatory or business-critical functionality
- Tier 2 – Annual Applications
- Count: Approx. 61–65 applications (remaining portfolio)
- Frequency: Minimum once per year
- Total annual tests: 61–65 tests/year
- These applications represent:
- Lower change frequency
- Controlled exposure
- Stable functionality with periodic updates
- Total Estimated Application Penetration Tests Per Year
- Tier 1: 54 tests
- Tier 2: 61–65 tests
- Total: ~115–119 tests annually
- Tier 3 – Red team engagements
- Count: 2 Red team engagements per year (Objective: Simulate realistic adversary behavior to assess the Security vulnerabilities)
- Mandatory Capabilities:
- 10+ years of experience in penetration testing.
- Deep expertise in OWASP Top 10, SANS Top 25, and MITRE ATT&CK framework.
- Proven experience in web, mobile, API, and infrastructure penetration testing.
- Strong reporting and communication skills.
- Red teaming experience
- Preferred Capabilities:
- OSCP, OSWE, OSCE, or equivalent certifications highly preferred.
- Experience with AI/ML security testing.
- Experience with cloud security testing (AWS, Azure, GCP).