Skip to content

Jobgether

Senior Penetration Testing Analyst

Location
India, IN
Arrangement
Remote
Employment type
Full-time
Level
Senior
Posted
24 September 2026 (7 days ago)

Checked 6 days agoApplications go to the employer, never to RoleSprint

About this role

Accountabilities: • Conduct advanced penetration testing and application security assessments across web applications, mobile applications, APIs, or network environments, depending on your area of specialization.

• Perform external and internal network penetration tests and vulnerability assessments using established methodologies and appropriate offensive security techniques.

• Use and, where appropriate, develop exploitation tools to conduct manual testing and identify vulnerabilities that automated assessments may overlook.

• Research emerging threats, vulnerabilities, attack techniques, and exploits to continuously strengthen penetration testing capabilities.

• Analyze vulnerabilities and exploitation paths, gather supporting evidence, and document findings clearly for client remediation.

• Produce professional security assessment reports that communicate vulnerabilities, exploit details, evidence, reproduction steps, risk context, and remediation recommendations.

• Lead client-facing discussions throughout engagements, including project kick-offs, notifications of high and critical findings, and close-out reviews.

• Explain complex technical findings clearly to clients and provide actionable recommendations for improving their security posture.

• Work independently to manage testing activities and deliverables while collaborating effectively with other members of the security team.

• Contribute to additional security initiatives and perform other responsibilities required to support penetration testing and threat research activities.

• Travel occasionally, with potential travel of up to 10% depending on engagement requirements.

Requirements

• 7+ years of related professional experience with a Bachelor’s degree, 5+ years with a Master’s degree, 3+ years with a PhD, or equivalent professional experience.

• At least 4 years of professional penetration testing experience.

• At least 4 years of hands-on experience with one or more offensive security tools such as Nmap, Metasploit, Kali Linux, or Burp Suite.

• Experience conducting application security testing, network penetration testing, or both; candidates may specialize in either application or network security.

• Strong knowledge of common application vulnerabilities and attack vectors, including the OWASP Top 10 and established security testing methodologies.

• Solid understanding of TCP/IP networking and practical knowledge of operating system administration and internals across Windows and/or Linux environments.

• Working knowledge of SQL and at least one high-level programming language.

• Offensive security certifications such as CEH, WAPT, GPEN, GWAPT, GAWN, OSCP, or equivalent credentials are valuable.

• Familiarity with additional application security tools such as Netsparker or AppScan is desirable.

• Strong analytical and problem-solving abilities, with a methodical approach to identifying, validating, and documenting vulnerabilities.

• Excellent written and verbal technical communication skills, particularly when explaining complex security findings to clients.

• Ability to work autonomously, take ownership of engagements, and collaborate effectively as part of a larger security team.

• Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical discipline is preferred, or equivalent professional experience.

• Legal authorization to work in India without requiring employer sponsorship.

Benefits

• Fully remote opportunity with a remote-first working model.

• Potential travel of up to 10% depending on client and engagement requirements.

• Opportunity to work on real-world penetration testing engagements across application and network security.

• Exposure to advanced offensive security techniques, emerging vulnerabilities, threat research, and exploitation methodologies.

• Opportunity to work with both established and internally developed security testing tools.

• Global collaboration with experienced cybersecurity professionals and security research teams.

• Employee-led diversity and inclusion communities supporting connection, learning, and advocacy.

• Volunteer and charitable initiatives that support local communities.

• Global sustainability initiatives and opportunities to contribute to environmental programs.

• Employee wellbeing programs, including wellbeing days, webinars, and health-focused training.

• Fitness, trivia, and other global employee activities designed to encourage connection and engagement.

• An inclusive environment that supports equal opportunity and accommodations throughout the recruitment process.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Work location

  • IN

Related jobs

Ready to make a decision?

This role is either worth your time or it isn’t.

Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.

Nothing is submitted automatically. You choose what happens next.

About this listing

Published on Lever under the board identifier Jobgether, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.

RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.

Published 24 September 2026, last checked 6 days ago. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.

Browse all current openings

No credit card requiredStart free