Skip to content

Open nowPosted 102 days ago

Security Engineer II

ibgllc180 open roles

Where
Mumbai, Maharashtra, India
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineer IIibgllc · Mumbai, Maharashtra, India
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on ibgllc's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 102 days ago

The posting

About the Role  We are looking for a Senior Penetration Tester who combines strong offensive testing skills with deep application security and secure code review expertise. This role is for someone who doesn't just test applications from the outside — you can read and reason about source code like a developer, trace vulnerable logic from input to sink, and then convert those code-level findings into real, working security test cases and exploits that prove impact end-to-end. You'll own full-cycle assessments: black-box testing, white-box/source-assisted review, and validation — tying it all together into a coherent risk narrative for engineering and leadership, with an attacker's mindset applied throughout. Exposure to broader red team operations is a plus and will allow you to extend application-layer footholds into wider adversary simulation scenarios.  Key Responsibilities  Application Penetration Testing (Black-box & White-box) 

Plan, scope, and execute end-to-end penetration tests on web applications, APIs, and mobile apps using both black-box and source-assisted (white-box) methodologies. 

Perform full attack-surface mapping, auth flows, session management, API contracts, business logic, access control boundaries - before diving into exploitation. 

Chain vulnerabilities together to demonstrate real business impact (e.g., IDOR + broken auth → account takeover; SSRF → internal pivot → sensitive data exposure). 

Validate and retest fixes; ensure remediations actually close the exploited path, not just the symptom. 

Manual Secure Code Review 

Conduct manual, in-depth secure code reviews across languages such as Java, Python, JavaScript/TypeScript (Node.js), Go, C#, and PHP — going beyond automated scanner output. 

Trace data flow from source (user input, external API, file upload, etc.) to sink (DB query, deserialization, template engine, OS command, file system, etc.) to confirm real exploitability and eliminate false positives. 

Identify vulnerability classes including injection attacks (SQL, NoSQL, Command, LDAP, XXE), insecure deserialization, authentication and session flaws, IDOR and broken access control, SSRF, race conditions, cryptographic misuse, and business logic flaws. 

Turning Code Findings into Working Security Tests 

For every significant code-review finding, build a corresponding proof-of-concept, exploit script, or test case that demonstrates exploitability in a running environment — not just a theoretical writeup. 

Develop custom scripts/tools (Python, Go, Bash) to weaponize and automate exploitation of identified code patterns across the codebase (e.g., identifying a vulnerable pattern, then scripting mass validation across multiple endpoints/services). 

Translate secure code review findings into repeatable regression security tests that can be reused across engagements and retesting cycles to catch reintroduction of the same bug class. 

Bridge the gap between "this line of code looks dangerous" and "here's the request/script/payload that proves it," making findings actionable and unambiguous for developers. 

Offensive Tooling & Automation 

Go beyond automated scan output — treat static/dynamic analysis as a recon and target-prioritization step, then manually validate and weaponize findings into working exploits, the way an attacker would triage a leaked or decompiled codebase. 

Build and maintain a personal/team exploit and payload library mapped to recurring vulnerability patterns — reusable proof-of-concepts, request templates, and scripts that turn a static finding into a live, demonstrable attack within minutes, speeding up engagement turnaround. 

Chain application-layer findings into deeper exploitation paths — e.g., using a discovered IDOR or auth flaw to escalate privileges within the app, or an SSRF/file-read bug to pivot into other exposed application components or internal services reachable from the app. 

Continuously stress-test your own exploit library and detection logic against the live application — attempt to bypass existing input validation, WAF rules, and app-layer guardrails to ensure findings reflect genuine adversary capability, not just tool coverage. 

Extending Findings into Red Team Scenarios (Good to Have) 

Use application-layer footholds (e.g., an SSRF, exposed internal endpoint, or leaked credential from source code) as an entry point into broader adversary simulation — pivoting from app compromise toward internal network or Active Directory attack paths where in scope. 

Apply working knowledge of C2 concepts (beaconing, traffic patterns, evasion) to understand how an application-layer compromise could realistically be leveraged for persistence or lateral movement in a full red team engagement. 

Bring an adversary-emulation mindset to engagements — thinking beyond "is this exploitable" to "how would a real threat actor chain this into a larger compromise." 

Reporting & Communication 

Author clear, detailed technical reports that connect the dots: vulnerable code snippet → proof-of-concept/exploit → business impact → remediation guidance. 

Map findings to OWASP Top 10, SANS Top 25, and CWE, with risk ratings and clear reproduction steps. 

Present findings to both engineering teams (code-level detail) and leadership (business risk, executive summary). 

Support developers during remediation — reviewing patches and confirming the fix addresses root cause, not just the trigger. 

Mentorship & Program Development 

Mentor junior pentesters/AppSec engineers on manual code review techniques and exploit development. 

Help mature the internal AppSec/pentest methodology — playbooks, custom tooling, and code-review checklists tailored to the tech stacks in use. 

Stay current with new vulnerability classes, framework-specific CVEs, and emerging exploitation techniques; incorporate them into review checklists and test cases. 

Required Qualifications 

5+ years in penetration testing / offensive security, with strong demonstrable experience in application security testing and manual secure code review (not just automated scanning). 

Proven ability to read and understand source code fluently in at least one major backend language (Java, Python, C#, Go, or JavaScript/TypeScript), enough to trace logic, understand data flow, and spot subtle flaws. 

Track record of converting static findings (from code review) into working dynamic proof-of-concepts — able to go from "vulnerable line of code" to an actual exploit/request/script that proves it. 

Strong scripting/programming skills (Python, Go, Bash, or similar) for building custom test scripts, automation, and exploit tooling. 

Solid understanding of web/API architecture and common vulnerability classes (OWASP Top 10, SANS Top 25, CWE). 

Hands-on experience with web/API application testing toolchains (e.g., Burp Suite Pro, Postman) and static/dynamic code analysis approaches. 

Strong report writing and communication skills, able to explain code-level vulnerabilities to both developers and non-technical stakeholders. 

Preferred Qualifications 

Certifications such as OSWE, OSCP, GWAPT, CRTE, or equivalent — OSWE especially valued given the code-review/exploit-dev focus. 

Prior red team experience — comfort with Active Directory attack paths, lateral movement, privilege escalation, and C2 frameworks (e.g., Cobalt Strike, Sliver, Metasploit) is a strong plus. 

Experience with mobile application security testing (iOS/Android) including static analysis of app binaries/source. 

Knowledge of compliance frameworks (PCI-DSS, ISO 27001, SOC 2) as they relate to application security testing. 

Active participation in bug bounty programs with a strong track record of validated findings is a plus. 

Speaking engagements at security/bug bounty conferences (e.g., DEF CON, Black Hat, Nullcon, c0c0n, BSides) or publishing security research/write-ups is a strong plus. 

Company Benefits & Perks: 

Competitive salary package. Performance based annual bonus (cash and stocks). Hybrid working model (3 days office/week). Group Medical & Life Insurance. Modern offices with free amenities & fully stocked cafeterias. Monthly food card & company paid snacks. Hardship/shift allowance with company provided pickup & drop facility* Attractive employee referral bonus. Frequent company sponsored team building events and outings.

* Depending upon the shifts. **The benefits package is subject to change at the management's discretion.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against ibgllc's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on ibgllc's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    ibgllc's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.