





Tier-1 brand, metro location, and mid-level experience increase competition despite niche security specialization.
Penetration-testing skills are transferable across industries but require domain-specific security experience.
Explicit 4+ years, required pen-testing skills and compliance experience make hiring filters stringent.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead and conduct manual and automated penetration tests for application-layer and network-layer security vulnerabilities in cloud infrastructure and applications.
Validate and prioritize security findings, coordinating with engineering and product teams to ensure effective remediation and compliance with standards such as PCI DSS and SOC.
Collaborate with external security firms and manage vulnerability assessments including bug bounty triage and post-remediation verification.
Minimum 4+ years of hands-on experience in penetration testing, ethical hacking, or application security engineering.
Strong knowledge of web application attacks (e.g., SQLi, XSS, CSRF) and mitigation techniques plus proficiency in scripting/programming (Python, Go, Ruby, or Bash).
Experience with security testing tools (BurpSuite Enterprise, SAST, DAST, IAST) and network protocols (TCP/IP, DNS, HTTP/S, TLS, IPSEC).
Relevant security certifications like OSCP, CEH, OSWE, or CISSP.
Experienced in conducting comprehensive security assessments and able to translate technical security findings to diverse audiences.
Familiarity with managing public bug bounty programs and automating security workflows using ChatOps or similar platforms.
Knowledgeable about cloud orchestration, infrastructure as code, containerization (Docker, Kubernetes), and compliance frameworks (ISO 27001, PCI DSS, SOC2).