AI Security and pentesting
eSec Forte TechnologiesGurugram, HR, IndiaSeptember 30, 2026
On-site
Full-time
Pentesting
Mid · 2–4 yrs
About the Role
This role involves conducting comprehensive security assessments and penetration tests across web applications, APIs, and advanced AI/LLM systems. You will be responsible for identifying vulnerabilities, developing proof-of-concept exploits, and delivering actionable remediation strategies to our diverse client base. The work includes hands-on technical execution, detailed reporting, and direct client engagement.
Key Responsibilities
- Perform in-depth penetration testing of web applications and APIs, identifying and exploiting vulnerabilities aligned with OWASP Top 10 and OWASP API Security Top 10.
- Conduct specialized security assessments for AI/LLM systems, including analysis of Agentic AI workflows and security considerations related to Model Context Protocol (MCP).
- Utilize tools such as Burp Suite for web and API vulnerability discovery, exploitation, and traffic manipulation during assessments.
- Develop clear, reproducible proof-of-concept exploits for identified vulnerabilities and provide detailed, practical remediation guidance to clients.
- Leverage vulnerability scanners like Tenable (Nessus) to perform network and application vulnerability assessments, interpreting results to prioritize and validate findings.
- Prepare comprehensive technical reports detailing assessment methodologies, findings, CVSS ratings, and strategic recommendations for various client stakeholders.
- Present assessment results to technical teams and executive audiences, articulating complex security issues and their business impact.
- Collaborate with internal teams to refine offensive security methodologies and contribute to the continuous improvement of AI security testing frameworks.
Requirements
- 2-4 years of hands-on experience in offensive security, specifically in penetration testing.
- BE/Btech degree.
- Demonstrated expertise in Web Application Penetration Testing and API Penetration Testing.
- Solid understanding of common application security vulnerabilities, including OWASP Top 10 and OWASP API Security Top 10.
- Practical experience with AI/LLM Security Testing, encompassing Agentic AI / AI Agent security and an understanding of MCP (Model Context Protocol).
- Proficiency with industry-standard penetration testing tools, including Burp Suite and vulnerability scanners like Tenable (Nessus).
- Ability to articulate technical security concepts and findings clearly in written reports and verbal presentations.
- This is an onsite role based in Gurugram, requiring client-side engagement.
Nice-to-Have
- Experience with Threat Modelling methodologies and frameworks.
- Exposure to Red Teaming exercises and adversary simulation techniques.
- Familiarity with scripting languages (e.g., Python, PowerShell) for developing custom exploitation tools or automating tasks.
- Experience with additional offensive security tools such as Nmap, Metasploit, or Cobalt Strike.
Benefits
- Health insurance for the employee and dependents
- Professional security-certification reimbursement (e.g., OSCP, OSWA)
- Annual learning and skill-development allowance
- Sponsored conference / training attendance
- Flexible work arrangements
Skills
web, api testing, AI/LLM testing, Threat modelling, red teaming
Qualification
BE/Btech
Job Details
Experience
Mid · 2–4 yrs
Tools & Tech
Burp Suite
Cobalt Strike
Metasploit
Nessus
Nmap
PowerShell
Python
Tenable
Preferred Certs
OSCP