Service Operations Specialist
- Hiring from
- India
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
We are seeking a highly skilled Offensive Security professional with expertise in Red Team Operations, Application Security Testing, API Security Assessment, Mobile Application Penetration Testing, and Dynamic Application Security Testing (DAST). The role involves simulating real-world cyberattacks, identifying security weaknesses across applications and infrastructure, and providing actionable remediation guidance to development and security teams.
Conduct adversary emulation exercises and Red Team engagements.
Execute attack simulations against enterprise environments, Active Directory, cloud infrastructure, and critical business applications.
Perform reconnaissance, initial access, privilege escalation, persistence, lateral movement, and data exfiltration simulations.
Assess effectiveness of SOC, SIEM, EDR, XDR, MDR, and Incident Response capabilities.
Develop custom attack scenarios based on MITRE ATT&CK framework.
Deliver executive and technical reports with attack paths, impact analysis, and remediation recommendations.
Perform manual and automated security assessments of web applications.
Identify and exploit vulnerabilities including:
SQL Injection
Cross-Site Scripting (XSS)
CSRF
SSRF
Broken Authentication
Authorization Bypass
Business Logic Flaws
File Upload Vulnerabilities
Perform REST, SOAP, GraphQL, and Microservices API security assessments.
Evaluate APIs against OWASP API Security Top 10.
Identify vulnerabilities such as:
Broken Object Level Authorization (BOLA)
Conduct Android and iOS application security assessments.
Perform static and dynamic analysis of mobile applications.
Assess:
Local Data Storage Security
- Configure and execute DAST scans across web applications and APIs.
- Validate and triage findings.
Integrate DAST into CI/CD and DevSecOps pipelines.
Assist development teams in remediation and secure coding practices.
Must-Have Skills:
- Offensive Security / Penetration Testing
- 5+ years of hands-on experience in Penetration Testing, Red Teaming, or Offensive Security.
- Strong understanding of adversary simulation and attack methodologies.
- Web & API Security
- Strong expertise in Web Application Security and API Security.
- OWASP Top 10 and OWASP API Top 10.
- Hands-on experience with Burp Suite, OWASP ZAP and similar tools.
- Network & Active Directory Security
- Network penetration testing and vulnerability assessment.
- Hands-on experience with Nmap, Metasploit, BloodHound, Cobalt Strike/equivalent.
- Knowledge of Active Directory attack techniques.
- Cloud & Infrastructure Security
- Hands-on security testing across Azure, AWS and/or GCP.
- Understanding of cloud attack paths, IAM, misconfigurations and cloud-native security.
- Red Team Tools, Scripting & Security Frameworks
- Strong hands-on experience with Kali Linux and offensive security tooling.
- Ability to develop attack/automation scripts using Python, PowerShell or Bash.
Working knowledge of MITRE ATT&CK, Secure SDLC and NIST CSF.
Good-to-have skills:
- Mobile & Advanced Application Security
- Mobile penetration testing using MobSF, Frida.
- Secure code review and advanced application security testing.
- Cloud Red Teaming & Container Security
- Cloud Red Teaming across Azure/AWS/GCP.
- Kubernetes, Docker and container security experience.
- DevSecOps & CI/CD Security
- Integration of security testing into CI/CD pipelines.
- DAST, threat modeling and DevSecOps practices.
- Purple Teaming & Adversary Emulation
- Experience conducting Purple Team exercises.
- Advanced adversary emulation and MITRE ATT&CK-based assessments.
- Industry Certifications
- Preferred: OSCP, OSEP, OSWE, CRTO, CRTP, PNPT, CISSP, GWAPT, GPEN, GMOB, GXPN or AZ-500.