hirly

SISA Information Security Pvt Ltd

Network Security

Bangalore, India

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at SISA Information Security Pvt Ltd first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.6M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Mid level
Country
IN
Work mode
On-site / unstated
First seen by hirly
23 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Experience: 7–10 years

Location: Bangalore

Employment Type: Full-time

Role Summary

We are looking for a senior offensive security professional with strong expertise in red team operations, adversary emulation, black-box network penetration testing, cloud penetration testing, phishing simulations, C2 operations, and custom exploit development .

The role requires hands-on capability to simulate real-world attacker behavior, develop attack paths, bypass security controls in authorized environments, and deliver high-quality technical findings with practical remediation guidance.

Key Responsibilities

  • Lead red team, adversary emulation, black-box network, cloud, and infrastructure penetration testing engagements.
  • Plan and execute attack scenarios covering reconnaissance, initial access, exploitation, privilege escalation, lateral movement, persistence, and objective-based actions.
  • Use adversary emulation platforms and C2 frameworks such as Cobalt Strike, Sliver, Mythic, Havoc, Metasploit, and similar tools in authorized assessments.
  • Design and execute phishing simulation campaigns, payload delivery scenarios, and initial access simulations.
  • Perform custom exploit development, exploit modification, payload customization, and proof-of-concept development for identified vulnerabilities.
  • Conduct Active Directory and hybrid identity attack simulations, including credential attacks, lateral movement, privilege escalation, and domain compromise scenarios.
  • Perform cloud penetration testing across AWS, Azure, and GCP , focusing on IAM abuse, exposed assets, storage misconfigurations, insecure networking, excessive permissions, and privilege escalation paths.
  • Assess endpoint, network, identity, cloud, and email security controls from an attacker’s perspective.
  • Support purple team and detection validation exercises by mapping techniques to MITRE ATT&CK .
  • Prepare detailed reports covering attack chains, exploited weaknesses, business impact, evidence, and remediation recommendations.
  • Present findings and attack narratives to technical teams, leadership, and client stakeholders.
  • Mentor junior team members and contribute to red team playbooks, tooling, labs, and methodologies.

Required Skills

  • Strong hands-on expertise in red teaming, adversary emulation, black-box testing, network penetration testing, and cloud pentesting .
  • Practical experience with C2 and adversary emulation platforms such as Cobalt Strike, Sliver, Mythic, Havoc, Metasploit, Covenant, or similar frameworks .
  • Experience in phishing simulations, payload delivery, social engineering assessments, and initial access simulation.
  • Ability to perform custom exploit development, exploit chaining, payload customization, and proof-of-concept creation.
  • Strong knowledge of Active Directory attack techniques, including Kerberoasting, AS-REP roasting, NTLM relay, pass-the-hash, pass-the-ticket, delegation abuse, ACL abuse, and domain escalation paths.
  • Good understanding of cloud attack techniques across AWS, Azure, and GCP , including IAM abuse, storage exposure, metadata service abuse, key leakage, role assumption, and privilege escalation.
  • Experience with tools such as BloodHound, Mimikatz, Impacket, NetExec/CrackMapExec, Responder, Evilginx, GoPhish, Nmap, Masscan, Nessus, Burp Suite, Wireshark, Hashcat, Hydra, Pacu, Prowler, ScoutSuite, AzureHound, ROADtools etc
  • Scripting and automation skills in Python, PowerShell, Bash, Go, or C/C++ .
  • Good understanding of OPSEC, payload handling, evasion concepts, attack path mapping, and detection-aware testing.
  • Strong reporting, stakeholder communication, and client-facing skills.

Good to Have

  • Experience with EDR/AV evasion testing in authorized environments.
  • Experience with malware analysis, reverse engineering, or implant customization.
  • Exposure to Kubernetes, Docker, and container security assessments.
  • Experience conducting purple team exercises and detection engineering support.
  • Certifications such as OSCP, OSEP, GPEN, GXPN, PNPT, eCPPT or CEH .
Original posting on SISA Information Security Pvt Ltd's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job