All jobs
InfoVision Inc. logo

Staff Penetration Tester

InfoVision Inc. · Posted today

  • Pune Division, Maharashtra, India (On-site)
  • Full-time
  • 8+ yrs

About the role

Summary

The Staff Penetration Tester is responsible for leading complex penetration testing and offensive security operations across enterprise infrastructure, applications, and cloud platforms. The Penetration Tester applies advanced threat modeling, exploitation techniques and tool expertise to uncover systemic weaknesses and evaluate organizational resilience. The role provides strategic guidance to technical and business stakeholders, drives remediation effectiveness, and contributes to red team simulations that test detection and response maturity. Success requires deep technical expertise, independent decision making, and the ability to communicate complex attack paths and risks clearly across teams to strengthen Bread Financials' security posture.

Minimum Qualifications

  • Bachelor’s Degree in Information Technology or Information Security or related field of study
  • At Least one (1) of the following: GPEN, GCPN, GWAPT, ECSA, OSCP, LPT Master, GRTP, or CRTE
  • 8+ years of experience in Information Security in reconnaissance, data exploitation, Web Application Testing (WAT), Active Directory (AD), scripting, automation, report writing and red teaming

Preferred Qualifications

  • Master’s Degree in Information Security or related field of study or equivalent, relevant work experience
  • 8+ years of Penetration Testing experience
  • Location : Bangalore

Roles & Responsibilities

Job Roles and Responsibilities

  • Plan, scope, and execute advanced penetration tests across web applications, internal networks, Active Directory environments, and cloud infrastructure, delivering actionable findings within agreed timelines.
  • Perform in-depth Active Directory security assessments, identifying misconfigurations, trust relationship abuses, and privilege escalation paths that expose the organization to insider and external threats.
  • Design and implement Test Automation scripts and security testing frameworks to reduce manual effort and ensure repeatable, consistent vulnerability identification across application deployments.
  • Continuously monitor web applications and security controls for emerging threats, zero-day vulnerabilities, and misconfigurations, recommending timely mitigations to engineering and DevSecOps teams.
  • Leverage RAG-based AI tools and large language model integrations to enhance threat intelligence gathering, automate vulnerability correlation, and accelerate security research workflows.
  • Produce high-quality technical and executive-level penetration test reports through strong Content Writing capabilities, clearly articulating risk severity, business impact, and step-by-step remediation guidance.
  • Collaborate with development, infrastructure, and compliance teams to validate security fixes, retest patched vulnerabilities, and ensure security standards are met before production deployments.
  • Serve as a subject matter expert and technical mentor to junior penetration testers, conducting knowledge transfer sessions, developing internal security playbooks, and contributing to the organization's overall security posture improvement.

Skills

penetration testingthreat modelingexploitation techniquesweb application testingscriptingautomationreport writingred teamingcloud infrastructure testingtest automationsecurity frameworks
Staff Penetration Tester at InfoVision Inc., Pune Division, Maharashtra, India (On-site) | Quark9