SISA Information Security Pvt Ltd
Network Security
Bangalore, India
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.6M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Mid level
- Country
- IN
- Work mode
- On-site / unstated
- First seen by hirly
- 23 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Experience: 7–10 years
Location: Bangalore
Employment Type: Full-time
Role Summary
We are looking for a senior offensive security professional with strong expertise in red team operations, adversary emulation, black-box network penetration testing, cloud penetration testing, phishing simulations, C2 operations, and custom exploit development .
The role requires hands-on capability to simulate real-world attacker behavior, develop attack paths, bypass security controls in authorized environments, and deliver high-quality technical findings with practical remediation guidance.
Key Responsibilities
- Lead red team, adversary emulation, black-box network, cloud, and infrastructure penetration testing engagements.
- Plan and execute attack scenarios covering reconnaissance, initial access, exploitation, privilege escalation, lateral movement, persistence, and objective-based actions.
- Use adversary emulation platforms and C2 frameworks such as Cobalt Strike, Sliver, Mythic, Havoc, Metasploit, and similar tools in authorized assessments.
- Design and execute phishing simulation campaigns, payload delivery scenarios, and initial access simulations.
- Perform custom exploit development, exploit modification, payload customization, and proof-of-concept development for identified vulnerabilities.
- Conduct Active Directory and hybrid identity attack simulations, including credential attacks, lateral movement, privilege escalation, and domain compromise scenarios.
- Perform cloud penetration testing across AWS, Azure, and GCP , focusing on IAM abuse, exposed assets, storage misconfigurations, insecure networking, excessive permissions, and privilege escalation paths.
- Assess endpoint, network, identity, cloud, and email security controls from an attacker’s perspective.
- Support purple team and detection validation exercises by mapping techniques to MITRE ATT&CK .
- Prepare detailed reports covering attack chains, exploited weaknesses, business impact, evidence, and remediation recommendations.
- Present findings and attack narratives to technical teams, leadership, and client stakeholders.
- Mentor junior team members and contribute to red team playbooks, tooling, labs, and methodologies.
Required Skills
- Strong hands-on expertise in red teaming, adversary emulation, black-box testing, network penetration testing, and cloud pentesting .
- Practical experience with C2 and adversary emulation platforms such as Cobalt Strike, Sliver, Mythic, Havoc, Metasploit, Covenant, or similar frameworks .
- Experience in phishing simulations, payload delivery, social engineering assessments, and initial access simulation.
- Ability to perform custom exploit development, exploit chaining, payload customization, and proof-of-concept creation.
- Strong knowledge of Active Directory attack techniques, including Kerberoasting, AS-REP roasting, NTLM relay, pass-the-hash, pass-the-ticket, delegation abuse, ACL abuse, and domain escalation paths.
- Good understanding of cloud attack techniques across AWS, Azure, and GCP , including IAM abuse, storage exposure, metadata service abuse, key leakage, role assumption, and privilege escalation.
- Experience with tools such as BloodHound, Mimikatz, Impacket, NetExec/CrackMapExec, Responder, Evilginx, GoPhish, Nmap, Masscan, Nessus, Burp Suite, Wireshark, Hashcat, Hydra, Pacu, Prowler, ScoutSuite, AzureHound, ROADtools etc
- Scripting and automation skills in Python, PowerShell, Bash, Go, or C/C++ .
- Good understanding of OPSEC, payload handling, evasion concepts, attack path mapping, and detection-aware testing.
- Strong reporting, stakeholder communication, and client-facing skills.
Good to Have
- Experience with EDR/AV evasion testing in authorized environments.
- Experience with malware analysis, reverse engineering, or implant customization.
- Exposure to Kubernetes, Docker, and container security assessments.
- Experience conducting purple team exercises and detection engineering support.
- Certifications such as OSCP, OSEP, GPEN, GXPN, PNPT, eCPPT or CEH .
Similar jobs
- Software Engineer | C/C++, System programming , Networking/Network security , Protocol development | 4-8 yearsCisco · Bangalore, IndiaFirst seen today
- Network Services Specialist - Managed Network Security ServicesKyndryl · Bangalore, Karnataka, IndiaFirst seen 2d ago
- Load Balancer-Network Security AdvisorNTT America, Inc. · Bangalore, Karnataka, IndiaFirst seen 2d ago
- CISAMRMFRE-Network Security JL3Infosys · Bangalore, IndiaFirst seen 6d ago
- CISAMRMFRE-Network Security-JL4Infosys · Bangalore, IndiaFirst seen 6d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job