Role & responsibilities
Lead and perform advanced manual penetration testing across web, mobile, APIs, cloud, and infrastructure environments.
Utilize Burp Suite Pro and other industry-standard tools for vulnerability identification, exploitation, and reporting.
Define and improve penetration testing methodologies, processes, and best practices.
Manage and mentor junior testers, reviewing their findings and ensuring quality deliverables.
Act as primary point of contact for security testing engagements with clients and internal stakeholders.
Provide strategic recommendations on risk remediation and secure development practices.
Align testing practices with security frameworks, including:
o OWASP ASVS v5
o OWASP Top 10 (2021)
o NIST 800-115
o ISO/IEC 27001/27002
o PCI DSS (where applicable)
Participate in threat modeling exercises, red team/blue team activities, and adversary simulations.
Prepare and present executive-level reports and conduct stakeholder briefings.
Stay ahead of emerging threats, tools, and techniques, and introduce relevant innovations into the testing practice.
Preferred candidate profile
Must to have skills-
Penetration testing, DAST Testing, SAST Testing, OWASP top 10
Preferred Qualifications
Certifications such as OSCP, OSWE, OSEP, GXPN, GWAPT, GPEN, Burp Suite Certified Practitioner.
Experience with red teaming / purple teaming.
Knowledge of regulatory frameworks (NIS2, GDPR, HIPAA, MDR).
Proven track record of handling large-scale or complex penetration testing projects.
Soft Skills
Strong leadership and decision-making skills.
Ability to balance technical depth with business risk considerations.
Excellent communication skills (executive reporting + technical deep dives).
Collaborative mindset with a focus on mentoring and developing talent.
Good to have Skills- Python

Keyskills: Security Testing DAST Testing Penetration Testing OWASP SAST Testing