+ Post Job +
Home Cybersecurity

Senior Penetration Tester

📍 Indore 🏷️ Cybersecurity 💰 ₹180,500 / month

Vijay Nagar in Indore has a Senior Penetration Tester opening, full time, on site, with a cybersecurity team running offensive security engagements for enterprise clients. Six and a half years of experience is the expectation, and the team wants someone who's actually broken into systems under real engagement constraints, not just run automated scanners and reported whatever came out.

The work covers assessing systems for vulnerabilities through hands-on testing, implementing protective controls where gaps get found, supporting incident response when a real issue surfaces during testing, and recommending improvements that reduce future risk in language a client's engineering team can actually act on. A penetration test that produces a scary report nobody knows how to fix isn't doing its job.

What you'll be doing

  • Conduct penetration tests across client applications and infrastructure
  • Implement or recommend protective controls based on findings
  • Support incident response when a genuine vulnerability is discovered during testing
  • Deliver findings and remediation guidance in client-ready reports

Required skills are penetration testing tools such as Burp Suite and Metasploit, solid networking fundamentals, and scripting ability for building custom exploitation or automation scripts when off-the-shelf tools fall short. A bachelor's degree in cybersecurity, information technology, or a related field is expected, along with a security certification such as CEH or CompTIA Security+ and proven familiarity with security monitoring, vulnerability assessment, and incident response.

Good to have

  • OSCP or a similarly hands-on offensive security certification
  • Experience with cloud-specific penetration testing methodology
  • Any background in bug bounty programs, which the team treats as legitimate real-world testing experience

Vijay Nagar has become a meaningful IT and business hub in Indore, and this security team's client engagements span industries with very different risk tolerances, from financial services clients who want exhaustive coverage to smaller businesses that need a more targeted, budget-conscious engagement scope.

Naukri Mitra has listed cybersecurity roles from this employer previously, and senior testers who've joined recently describe the report-writing side of the job as underrated in how much it's actually weighted during review; a technically brilliant finding that's poorly communicated to a client's non-security engineering team ends up unfixed far more often than a clearly explained one.

Interviews include a hands-on technical assessment against a test environment and a discussion of a past engagement's most interesting finding. Candidates who can explain a complex vulnerability in plain language during that conversation tend to interview well.

The Indore office itself is a fairly typical mid-size setup, with the Cybersecurity team sharing space with a couple of other functions rather than occupying a dedicated floor. That layout means visibility works both ways: good work gets noticed by people outside the immediate team faster than it might at a larger, more siloed employer, and so do mistakes.

Scope creep during an engagement is a real risk in this line of work, and the team has a clear internal rule that any testing outside the agreed scope, even something that looks trivially exploitable, gets flagged to the client for explicit sign-off before proceeding, no exceptions.

Engagement lengths here vary from a focused two-week application test to a multi-month infrastructure assessment, and senior testers are expected to scope their own time allocation across concurrent engagements, a level of self-management that's explicitly discussed during the interview process rather than assumed.

Each engagement wraps with an internal debrief separate from the client-facing report, where the team discusses what techniques worked, what didn't, and what should change for next time, a practice the lead has credited with steadily improving the team's methodology over several years rather than letting hard-won lessons quietly disappear.

The security team maintains an internal library of past engagement findings, anonymized by industry, and testers are encouraged to reference relevant entries when scoping a new engagement, since certain vulnerability patterns recur predictably across similar types of client applications.

Benefits

  • Health insurance covering the employee and immediate family
  • Paid time off
  • Performance-linked bonuses
  • Relocation assistance and accommodation support for candidates moving to Indore

This role is based at Vijay Nagar, Indore, pin code 452010, five days a week on site. Pay runs up to ₹1,80,500 a month. The team hopes to fill this seat within six to seven weeks.

Frequently Asked Questions

OSCP or a similarly hands-on offensive security certification is listed as a plus, though the team also treats bug bounty experience as legitimate real-world testing background.
It gets flagged to the client for explicit sign-off before proceeding, even if it looks trivially exploitable. There are no exceptions to that rule.
Anywhere from a focused two-week application test to a multi-month infrastructure assessment, and senior testers scope their own time across concurrent engagements.
Report writing. A technically strong finding that's poorly communicated to a client tends to go unfixed far more often than one explained clearly.
Pay runs up to ₹1,80,500 a month, and the team hopes to fill the seat within six to seven weeks.
Apply Now