CareCloud is looking for a skilled Penetration Tester to evaluate the security of applications, networks, systems, and cloud environments through authorized offensive security testing. The role involves identifying vulnerabilities, simulating real-world cyberattacks, and providing actionable recommendations to improve security posture.
Key Responsibilities
- Conduct penetration tests across web, mobile, API, network, and infrastructure environments.
- Validate identified vulnerabilities and assess their potential business impact.
- Prepare comprehensive and detailed penetration testing reports.
- Perform vulnerability assessments and conduct thorough security reviews.
- Collaborate with development and infrastructure teams to guide remediation efforts.
- Support red team exercises and adversary simulation activities to enhance defense strategies.
- Stay updated on emerging attack techniques and evolving security threats through continuous research.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, or a related discipline.
- Minimum of 4 years’ experience in penetration testing.
- Strong understanding of offensive security methodologies and best practices.
- Proficiency with various penetration testing tools and frameworks.
Preferred Qualifications and Benefits
- Certifications such as OSCP (Offensive Security Certified Professional), GPEN (GIAC Penetration Tester), GWAPT (GIAC Web Application Penetration Tester), or CEH (Certified Ethical Hacker) are highly desirable.
Skills Required
- Expertise in penetration testing and vulnerability assessment.
- In-depth knowledge of web application security and network security testing.
- Experience with API security testing and exploit validation.
- Ability to produce clear and actionable security reports.
- Competence in threat simulation and adversary emulation techniques.
The position offers a competitive monthly salary ranging from Rs150,000 to Rs250,000. This role requires working on-site to effectively collaborate with teams and conduct hands-on security assessments.