Senior Penetration Tester & Red Teamer
Lead offensive security assessments, advanced black-box web/API pentesting, and red team adversary simulations for enterprise clients.
Role Overview & Operational Scope
As a Senior Penetration Tester at Cehpoint, you will protect high-stakes infrastructure by thinking like an adversary. You will lead black-box and white-box engagements across web apps, APIs, cloud environments, and internal networks, working directly with client CISOs and our senior engineering leadership.
Key Responsibilities & Production Deliverables
- Perform advanced web application, API, and mobile application penetration tests following OWASP Top 10 and WSTG standards.
- Execute network infrastructure vulnerability assessments and internal Active Directory red team simulations.
- Evaluate cloud security configurations on AWS, OCI, and Azure environments for privilege escalation paths.
- Develop custom exploit scripts and automated proof-of-concept tools in Python or Bash.
- Draft executive-ready vulnerability reports with clear CVSS scoring, risk impact analyses, and actionable remediation steps.
- Conduct debrief meetings with client technical teams to guide remediation and perform re-testing validation.
Mandatory Foundational Knowledge
- Deep foundational understanding of TCP/IP networking, DNS, firewalls, and HTTP/S protocol internals.
- Thorough mastery of OWASP Top 10 vulnerabilities (SQLi, SSRF, XSS, IDOR, Broken Authentication, Deserialization).
- Strong knowledge of Active Directory attack vectors (Kerberoasting, Pass-the-Hash, DCSync) and privilege escalation.
- Familiarity with enterprise compliance standards (ISO 27001, CERT-In guidelines, PCI-DSS, DPDP Act).
Mandatory Practical Skills & Architecture
- Hands-on expertise with Burp Suite Professional, Nmap, Wireshark, Metasploit Framework, and BloodHound.
- Proficiency in Python, Bash, or Go for custom exploit and payload automation.
- Demonstrated ability to perform manual API pentesting (REST, GraphQL, WebSocket endpoints).
- Experience drafting professional vulnerability assessment reports with zero copy-paste fluff.
Problem Solving, Execution Rigor & Curiosity
- Continuous research into newly published CVEs, zero-day research, and emerging threat actor techniques.
- Relentless dedication to ethical hacking ethics, responsible disclosure, and high professional integrity.
- Passion for automating repetitive security tasks while maintaining sharp manual investigative instincts.
5-Day Live Technical Evaluation Milestone
5-Day Live Practical Security Milestone: Conduct a comprehensive black-box vulnerability assessment on our designated staging target, identify critical security gaps, and submit a professional, proof-of-concept remediation report (strictly within 5 working days). Successful validation triggers immediate official corporate offer letter issuance.
Institutional Hiring Protocol: Candidates who pass initial resume screening are invited to a live, practical evaluation milestone spanning strictly not more than 5 working days. Verifiable completion and code audit by your assigned senior engineering mentor is the sole prerequisite for official corporate offer letter issuance.
Compensation, Total Rewards & Advancement
- Competitive senior salary (₹8,00,000–₹15,00,000) with performance and project-completion bonuses.
- 100% remote work flexibility with home-office equipment support.
- Sponsored security certifications (OSCP, CRTP, CEH Master) and lab subscriptions.
- Direct leadership exposure working on mission-critical national and international client deployments.
Dedicated Inquiries Inbox for This Role
Have questions regarding architecture scope or wish to share private research repos directly? Messages sent to this address route straight to the engineering leads reviewing this opening.
senior-penetration-tester-red-te-careers@cehpoint.co.in
Open Mail Client →