Skip to content

Network Security

SISA Information Security Pvt LtdBengaluru, KA, IndiaAugust 5, 2026
On-site
Full-time
Pentesting
Senior · 7–10 yrs

Experience: 7–10 years

Location: Bangalore

Employment Type: Full-time

Role Summary

We are looking for a senior offensive security professional with strong expertise in red team operations, adversary emulation, black-box network penetration testing, cloud penetration testing, phishing simulations, C2 operations, and custom exploit development.

The role requires hands-on capability to simulate real-world attacker behavior, develop attack paths, bypass security controls in authorized environments, and deliver high-quality technical findings with practical remediation guidance.

Key Responsibilities

  • Lead red team, adversary emulation, black-box network, cloud, and infrastructure penetration testing engagements.
  • Plan and execute attack scenarios covering reconnaissance, initial access, exploitation, privilege escalation, lateral movement, persistence, and objective-based actions.
  • Use adversary emulation platforms and C2 frameworks such as Cobalt Strike, Sliver, Mythic, Havoc, Metasploit, and similar tools in authorized assessments.
  • Design and execute phishing simulation campaigns, payload delivery scenarios, and initial access simulations.
  • Perform custom exploit development, exploit modification, payload customization, and proof-of-concept development for identified vulnerabilities.
  • Conduct Active Directory and hybrid identity attack simulations, including credential attacks, lateral movement, privilege escalation, and domain compromise scenarios.
  • Perform cloud penetration testing across AWS, Azure, and GCP, focusing on IAM abuse, exposed assets, storage misconfigurations, insecure networking, excessive permissions, and privilege escalation paths.
  • Assess endpoint, network, identity, cloud, and email security controls from an attacker’s perspective.
  • Support purple team and detection validation exercises by mapping techniques to MITRE ATT&CK.
  • Prepare detailed reports covering attack chains, exploited weaknesses, business impact, evidence, and remediation recommendations.
  • Present findings and attack narratives to technical teams, leadership, and client stakeholders.
  • Mentor junior team members and contribute to red team playbooks, tooling, labs, and methodologies.

Required Skills

  • Strong hands-on expertise in red teaming, adversary emulation, black-box testing, network penetration testing, and cloud pentesting.
  • Practical experience with C2 and adversary emulation platforms such as Cobalt Strike, Sliver, Mythic, Havoc, Metasploit, Covenant, or similar frameworks.
  • Experience in phishing simulations, payload delivery, social engineering assessments, and initial access simulation.
  • Ability to perform custom exploit development, exploit chaining, payload customization, and proof-of-concept creation.
  • Strong knowledge of Active Directory attack techniques, including Kerberoasting, AS-REP roasting, NTLM relay, pass-the-hash, pass-the-ticket, delegation abuse, ACL abuse, and domain escalation paths.
  • Good understanding of cloud attack techniques across AWS, Azure, and GCP, including IAM abuse, storage exposure, metadata service abuse, key leakage, role assumption, and privilege escalation.
  • Experience with tools such as BloodHound, Mimikatz, Impacket, NetExec/CrackMapExec, Responder, Evilginx, GoPhish, Nmap, Masscan, Nessus, Burp Suite, Wireshark, Hashcat, Hydra, Pacu, Prowler, ScoutSuite, AzureHound,  ROADtools etc
  • Scripting and automation skills in Python, PowerShell, Bash, Go, or C/C++.
  • Good understanding of OPSEC, payload handling, evasion concepts, attack path mapping, and detection-aware testing.
  • Strong reporting, stakeholder communication, and client-facing skills.

Good to Have

  • Experience with EDR/AV evasion testing in authorized environments.
  • Experience with malware analysis, reverse engineering, or implant customization.
  • Exposure to Kubernetes, Docker, and container security assessments.
  • Experience conducting purple team exercises and detection engineering support.
  • Certifications such as OSCP, OSEP, GPEN, GXPN, PNPT, eCPPT or CEH.

Job Details

Salary

₹2,500,000 – ₹3,500,000/yr

Experience

Senior · 7–10 yrs

Tools & Tech

Active Directory
AWS
Azure
Bash
Burp Suite
C
Cobalt Strike
C++
Docker
GCP
Go
Kubernetes
Metasploit
Nessus
Nmap
PowerShell
Python

Preferred Certs

GPEN
OSCP
OSEP