information security consultant
eSec Forte TechnologiesThane, MH, IndiaSeptember 30, 2026
On-site
Full-time
Pentesting
Mid · 1–4 yrs
About the Role
This role involves conducting comprehensive security assessments across diverse digital assets, identifying vulnerabilities, and providing actionable remediation strategies. You will apply hands-on expertise in penetration testing and vulnerability analysis for web, API, mobile, and network environments, directly contributing to enhancing client security postures through detailed analysis and reporting of identified risks.
Key Responsibilities
- Execute in-depth vulnerability assessment and penetration testing (VAPT) for web applications, APIs, and mobile applications, meticulously identifying security flaws such as those outlined in the OWASP Top 10, OWASP API Security Top 10, and OWASP Mobile Top 10.
- Perform comprehensive network penetration tests, encompassing both internal and external infrastructure, to uncover misconfigurations, unpatched systems, and exploitable vulnerabilities across various network devices, operating systems, and cloud environments.
- Utilize industry-leading and proprietary security testing tools, including Burp Suite (PortSwigger) for advanced web and API security analysis, Tenable (Nessus) for network vulnerability scanning, and potentially OpenText (Fortify) or Checkmarx for static analysis insights.
- Analyze security configurations of diverse IT assets, including servers, workstations, firewalls (e.g., Palo Alto Networks), intrusion prevention systems, and other network components, providing actionable recommendations for hardening and compliance.
- Develop detailed, high-quality technical reports that clearly document identified vulnerabilities, assess their potential business impact, demonstrate proof-of-concept exploits, and provide precise, practical remediation steps for client teams.
- Collaborate effectively with client development, operations, and security teams to articulate findings, discuss mitigation strategies, and support the successful implementation of security enhancements.
- Actively research and stay updated on emerging threats, attack techniques, security tools, and industry best practices relevant to application, API, mobile, and network security, contributing to internal knowledge sharing.
- Participate in post-assessment reviews, provide expert guidance on security improvements, and contribute to the continuous refinement of testing methodologies and internal security processes.
Requirements
- 1-4 years of dedicated, hands-on experience in information security, with a strong focus on penetration testing and vulnerability assessment.
- Demonstrated expertise in conducting comprehensive security testing across web applications, APIs, mobile applications (Android/iOS), and diverse network infrastructures.
- Profound understanding of common web application vulnerabilities (e.g., OWASP Top 10), mobile application security risks (e.g., OWASP Mobile Top 10), and network attack vectors and exploitation techniques.
- Proficiency with leading security testing tools such as Burp Suite (PortSwigger), Nmap, Metasploit, Tenable (Nessus), or similar open-source and commercial solutions.
- Familiarity with various operating systems (Linux, Windows, macOS) and network protocols (TCP/IP, HTTP/S, DNS, SMTP, etc.), including common enterprise technologies.
- Exceptional analytical skills to identify complex security flaws, assess their potential impact on business operations, and propose effective countermeasures.
- Strong technical report writing capabilities, including the ability to create clear, concise, and actionable findings, coupled with excellent verbal communication skills to articulate findings and recommendations to both technical and non-technical audiences.
- Any graduate degree.
Nice-to-Have
- Specialized experience in advanced web and API penetration testing methodologies, including business logic flaws, authentication bypasses, and server-side request forgery (SSRF).
- Experience with scripting languages (e.g., Python, PowerShell, Bash) for automating security tasks, developing custom exploits, or performing data analysis.
- Relevant industry certifications such as Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), or equivalent.
- Familiarity with cloud security concepts (AWS, Azure, GCP) and associated testing techniques, including container security and serverless functions.
Benefits
- Health insurance for the employee and dependents
- Professional security-certification reimbursement (e.g., OSCP, CEH)
- Annual learning and skill-development allowance
- Sponsored conference / training attendance
- Flexible work arrangements
Skills
web+api+mobile+network testing, web+api testing
Qualification
Any graduate
Job Details
Experience
Mid · 1–4 yrs
Tools & Tech
AWS
Azure
Bash
Burp Suite
Checkmarx
GCP
Linux
macOS
Metasploit
Nessus
Nmap
Palo Alto
PowerShell
Python
Tenable
Windows
Preferred Certs
CEH
OSCP