← Browse all jobs

T

Security Engineer - OSCP

TAC Security · India

FULL TIME

Job Description

Role Purpose

TAC Security is looking for a highly skilled Security Engineer – OSCP Certified with strong hands-on expertise in penetration testing, vulnerability assessment, application security, network security, and offensive security .

The Security Engineer will be responsible for identifying, validating, and demonstrating security vulnerabilities across web applications, APIs, mobile applications, networks, cloud environments, and infrastructure. The role requires a strong offensive-security mindset, practical exploitation skills, and the ability to provide actionable remediation guidance to clients and internal teams.

Key Responsibilities

1. Vulnerability Assessment & Penetration Testing

  • Perform end-to-end Vulnerability Assessment and Penetration Testing (VAPT) across applications and infrastructure.
  • Conduct manual penetration testing rather than relying solely on automated scanning tools.
  • Identify, validate, exploit, and document security vulnerabilities.
  • Perform network and infrastructure penetration testing across internal and external environments.
  • Conduct security testing of web applications, APIs, mobile applications, and cloud-based environments.
  • Perform vulnerability verification and retesting after remediation.
  • Evaluate vulnerabilities based on technical severity, exploitability, and potential business impact.

2. Web Application & API Security

  • Perform advanced web application penetration testing aligned with OWASP Top 10 and relevant testing methodologies.
  • Test for vulnerabilities including SQL Injection, XSS, SSRF, IDOR, authentication and authorization weaknesses, insecure deserialization, file-upload vulnerabilities, business-logic flaws, and security misconfigurations.
  • Conduct API security assessments covering REST and other API architectures.
  • Identify complex authorization, authentication, session-management, and business-logic vulnerabilities.

3. Network & Infrastructure Security

  • Conduct external and internal network penetration testing.
  • Perform network enumeration, service discovery, vulnerability analysis, exploitation, and privilege escalation.
  • Assess Windows and Linux environments for security weaknesses.
  • Conduct Active Directory security assessments and identify privilege-escalation and lateral-movement opportunities.
  • Evaluate firewall configurations, exposed services, network segmentation, and infrastructure security controls.

4. Offensive Security & Exploitation

  • Apply OSCP-level penetration-testing techniques in real-world environments.
  • Perform manual exploitation, privilege escalation, pivoting, lateral movement, and post-exploitation activities within approved scopes.
  • Develop or modify scripts and proof-of-concept exploits when required.
  • Use offensive-security techniques responsibly and strictly within authorized testing environments.
  • Maintain detailed evidence and attack paths throughout engagements.

5. Security Tools & Technologies

Hands-on experience with tools such as:

  • Burp Suite Professional
  • Nmap
  • Metasploit
  • Nessus
  • Kali Linux
  • Wireshark
  • BloodHound
  • Impacket
  • SQLMap
  • Nikto
  • Gobuster/Ffuf
  • Hydra
  • John the Ripper/Hashcat

Candidates should understand the underlying techniques and be capable of performing manual validation rather than depending exclusively on tools.

6. Reporting & Remediation

  • Prepare detailed and professional penetration-testing reports containing vulnerability descriptions, severity, evidence, proof of concept, business impact, and remediation recommendations.
  • Assign severity using appropriate methodologies such as CVSS .
  • Conduct technical walkthroughs with customers, developers, security teams, and management.
  • Work closely with engineering teams to explain vulnerabilities and recommend practical remediation.
  • Perform remediation validation and closure testing.

7. Research & Continuous Improvement

  • Stay updated on emerging vulnerabilities, CVEs, exploitation techniques, attack methodologies, and cybersecurity threats.
  • Research new offensive-security techniques and tools.
  • Contribute to internal security methodologies, testing checklists, knowledge bases, automation, and security research.
  • Participate in internal knowledge-sharing and technical training sessions.

Required Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
  • OSCP (Offensive Security Certified Professional) certification is mandatory.
  • 3–7+ years of hands-on experience in penetration testing, VAPT, offensive security, or application security.
  • Strong practical knowledge of:
  • Web Application Penetration Testing
  • API Security Testing
  • Network Penetration Testing
  • Active Directory Security
  • Linux & Windows Privilege Escalation
  • Vulnerability Assessment
  • Exploitation & Post-Exploitation
  • OWASP Top 10
  • CVSS
  • Strong understanding of TCP/IP, DNS, firewalls, VPNs, proxies, authentication protocols, and network architectures.
  • Ability to write basic automation/exploitation scripts using Python, Bash, or PowerShell .
  • Excellent analytical, troubleshooting, documentation, and communication skills.

Preferred Qualifications

Additional certifications such as OSWE, OSEP, CRTP/CRTE, PNPT, GPEN, GWAPT, CEH, or eJPT would be advantageous.

Experience in one or more of the following would also be valuable: cloud penetration testing across AWS/Azure/GCP, mobile application security, source-code review, DevSecOps/AppSec, red teaming, threat modeling, or secure-code review.

Details

CompanyTAC Security
LocationIndia
TypeFULL TIME
Nichegeneral

Similar Jobs

D

Commercial Operations Associate

Danaher

B

Information security analyst

Banyan Cloud

A

Strategy manager - (mbbs qualified)

Anonymous

A

Faculty - quantitative aptitude / maths (99%ile+ cat qa)

AceIPM

J

Assistant professor

Jain