•
Proposed designation:
Manager-Penetration Testing
•
Role type:
Permanent
•
Reporting to: Associate Director
•
Geo to be supported:
KDNI
•
Work timings:
Flexible
Roles & responsibilities
•
Lead a team of penetration testers for large, multi-year engagements
across diverse technology stacks.
•
Define and enforce testing methodologies (OWASP, PTES, OSSTMM, NIST SP
800-115) and quality standards.
•
Perform and oversee penetration testing across Web, APIs, Infra/Cloud,
Mobile, Thick/Thin clients, SAP, and AI/ML (not necessarily all, but
multiple areas at depth).
•
Conduct remote client workshops to enhance service delivery and
collaborate on improvements.
•
Create automation tools and scripts (Python, Power Platform, Power BI,
VBA, Bash/PowerShell) to improve efficiency.
•
Deliver detailed technical reports and executive summaries with CVSS v4.0
scoring and remediation guidance.
•
Engage with technical and non-technical stakeholders to explain findings,
remediation options, and risk implications.
•
Mentor junior team members on advanced testing techniques and tools.
•
Partner with Cybersecurity teams to develop new testing techniques and
automation strategies.
•
Ensure compliance with legal, ethical, and safe-harbor guidelines during
all testing activities.
Educational qualifications
•
Minimum Bachelor's degree in Computer Science, Information Technology or
MCA.
•
One or more relevant certifications, preferred: CEH, OSCP, OSCE, OSEE,
CISSP, or CREST.
•
Bonus: CISSP, CCSP (for broader leadership/context).
Work experience
•
12+ years of recent experience in penetration testing of web applications,
API or network devices.
•
Hands-on experience with industry-standard tools: Burp Suite, OWASP ZAP,
Metasploit, Nmap, Nessus/OpenVAS, MobSF, Frida, Ghidra, SAP security
tools.
•
Proficiency in scripting and automation: Python, PowerShell, Bash, Power
Platform, Power BI, VBA.
•
Vulnerability assessment and web application, API, network pentesting.
•
Experience with CVSS v4.0 scoring and mapping findings to frameworks
(OWASP Top 10, MITRE ATT&CK, CWE).Familiarity with DevSecOps pipelines
and CI/CD integration for automated testing.
•
Knowledge of mobile application pentesting, application security,
vulnerability management, configuration reviews, security operations and
monitoring or security architecture design would be an added advantage.
Strong technical report writing and ability to communicate findings to
both technical and business audiences
Key behavioral attributes/requirements
·
Strong stakeholder management skills; capable of running workshops and
influencing remediation decisions.
·
Ability to lead and motivate a team of pentesters across complex,
multi-phase engagements.
·
Ability to prioritize vulnerabilities based on business impact and risk
context.
·
Excellent customer service and communication (oral / written) skills
required.
Comfortable working in dynamic environments and across diverse technology
landscapes
•
Interview process:
3
•
Does the job role involve travelling:
No
•
Does the busy season apply to this role?:
No