Sign up to access all features of our service
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Penetration Tester, Security Testing

Qualys

Pune
  • Remote job

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Job Description:
We are seeking a skilled Penetration Tester to assess and enhance the security of our cross-platform executable Qualys Cloud Agent.
This agent is responsible for system monitoring, data collection, and secure communication with a cloud platform.
Operating across Unix, Windows, and macOS environments, the agent plays a critical role in our security and compliance solutions.
The ideal candidate will uncover vulnerabilities, simulate attack scenarios, and work with our teams to fortify the system against threats.
Key Responsibilities:
Cross-Platform Agent Testing:
Conduct comprehensive security testing of the executable agent, ensuring robust functionality across Unix/Linux, Windows, and macOS platforms.
Identify and exploit vulnerabilities in the agent’s runtime behavior, system interactions, and interprocess communications.
Test agent privilege management and evaluate risks of escalation or exploitation.
Data Collection and Handling:
Analyze the agent’s data collection mechanisms to ensure data privacy and integrity.
Validate proper implementation of sensitive data redaction and secure storage practices.
Communication Security:
Test the agent’s secure communication mechanisms with the cloud server, focusing on:
Encryption (TLS/SSL, public key cryptography).
Authentication and session management.
Mitigation of threats like MITM, replay attacks, and DNS spoofing.

Reverse Engineering and Exploitation:
Perform binary analysis to identify vulnerabilities in the agent's implementation.
Reverse engineer agent components to assess the effectiveness of tamper-proofing mechanisms and embedded security features.
Simulate advanced threat scenarios, including code injection and runtime manipulation.
System Security Evaluations:
Assess the agent’s impact on host system security, ensuring it does not inadvertently introduce risks (e.g., open ports, exploitable configurations).
Evaluate installation, update, and self-defense mechanisms for tamper resistance and exploitation risks.
Reporting and Remediation:
Provide detailed vulnerability reports with proof of concept (PoC), risk impact assessments, and actionable remediation steps.
Collaborate with development team to address vulnerabilities and validate fixes
Contribute to improving secure development practices and robust agent design.
Required Qualifications:
Technical Expertise:
In-depth knowledge of penetration testing methodologies for executable agents, system processes, and OS-specific security models (Windows, Unix/Linux, macOS).
Proficiency in network security and cryptographic protocol testing.
Strong background in reverse engineering tools and techniques
Tools & Scripting:
Scripting skills in Python, Bash, PowerShell, for creating custom tests.
Hands on experience with proxy solutions ex Burp or Fiddler
Experience:
Proven track record of assessing software agents or similar system monitoring tools.
Familiarity with common vulnerabilities, including CVEs related to agent-based applications.
Experience working with security tools or platforms similar to Qualys Agent.
Certifications (Preferred):
OSCP, OSWE, CEH, GPEN, or equivalent cybersecurity certifications.
Relevant cloud certifications such as AWS Security Specialty, Azure Security Engineer Associate.
Preferred Qualifications:
Hands-on experience with agent technologies similar to Qualys Cloud Agent.
Familiarity with cloud architecture, APIs, and integration points.
Knowledge of secure coding practices and defensive programming.
Experience with CI/CD pipeline security.

Vacancy posted more than 2 months ago
Similar jobs that could be interesting for youBased on the Penetration Tester, Security Testing in Pune vacancy
  • Role : Senior Security Penetration Tester Location : Hyderabad / Pune (Hybrid) Shift : 4:30 PM IST - 1:30 AM IST (Supporting US & LatAm Stakeholders...  ...services (S3, EC2, Lambda, API Gateway, SNS, etc.) - Thick Client/Desktop applications using reverse engineering techniques and... 
    Suggested
    Hybrid work
    Shift work

    Dexian

    Pune
    4 days ago
  •  ...Join us as a Penetration Tester in Barclays, responsible for supporting the successful delivery of...  ...Infrastructure. APIs. Mobile Apps. Thick clients. MCPs/AI Agents/LLMs. Cloud environments. Understanding of the security mechanisms associated with Applications,... 
    Suggested
    Permanent employment

    Barclays

    Pune
    more than 2 months ago
  •  ...is on a mission to stop breaches simplify security and shape the future of cyber defense. We...  ...collaboration with U.S.-based teams and clients you will be expected to work during overlapping...  ...solutions into enterprise SIEM SOAR and endpoint security ecosystems. Strong... 
    Suggested
    Full time
    Hybrid work
    Work at office
    Local area
    Remote job
    Worldwide
    Home office

    Critical Start

    Pune
    13 days ago
  •  ...Join us as a “Senior Penetration Tester" at Barclays, where you'll spearhead the evolution of our...  ...Web applications, APIs, mobile & Thick Clients Infrastructure and networks Virtualization...  ...and Kubernetes) Understanding of the security mechanisms associated with Applications... 
    Suggested
    Long term contract
    Permanent employment
    Temporary work

    Barclays

    Pune
    more than 2 months ago
  •  ...our team and start your journey today! Security Engineer Job Description The...  ...Protocol reverse engineering Conduct manual penetration testing including but not limited to:...  ...secure and that we are protecting our clients from relevant cyber threats by proactively... 
    Suggested
    Full time
    Start today
    Flexible hours

    Copeland

    Pune
    28 days ago
  • Description :The Security Engineer is the day-to-day execution arm of our security function...  ..., and M365 : SIEM, EDR (Defender for Endpoint), CSPM, and cloud-native logging (CloudTrail...  ...assessments and coordinate external penetration tests; manage findings to closure.- Support... 
    Hybrid work
    Work at office

    Synapse XTL

    Pune
    4 days ago
  •  ...30 years of financial experience and over 22000 partners we serve the worlds most sophisticated clients using leading technology and exceptional service. The APAC Security Operations/Engineering organization is seeking a junior to mid-level associate developer to join... 
    Full time
    Work at office
    Flexible hours

    Northern Trust

    Pune
    29 days ago
  •  ...: Experienced (relevant combo of work and education) Product Security Engineer -/Pune - 7- to 10yrs Are you curious, motivated, and...  ...information that we process in order to provide services to our clients. For specific information on how FIS protects personal... 
    Full time

    FIS

    Pune
    14 days ago
  •  ...implementing improvements Resource & Budget Management: Forecast and secure necessary technical resources (engineers, architects, QA, DevOps)...  ...75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible... 
    Full time
    Hybrid work
    Work at office
    Remote job
    Flexible hours
    Shift work

    NTT DATA Services

    Pune
    7 days ago
  •  ...Sr. Security Compliance Engineer Responsibilities Engineering & Implementation: Designing and implementing secure compliant...  ...procedures relevant security standards best practices regulations and client requirements to identify gaps and provide remediation solutions.... 
    Full time

    Pratiti Technologies Pvt. Ltd.

    Pune
    27 days ago
  •  ...Job Title: Cybersecurity Analyst / Security Operations Analyst   Who are we Fulcrum Digital is an agile and next-generation...  ...Microsoft Sentinel, Nessus, Sophos, and Microsoft Defender for Endpoint. Adept at investigating phishing threats, building insightful Power... 
    Full time

    Fulcrum Digital

    Pune City
    21 days ago
  •  ...technologies that drive modern organizations. Since 2011 our mission hasnt changed were here to stop breaches and weve redefined modern security with the worlds most advanced AI-native platform. We work on large scale distributed systems processing almost 3 trillion events per... 
    Full time
    Work at office
    Local area

    CrowdStrike

    Pune
    25 days ago
  •  ...respect the diversity and dignity of our employees and recognize their merit. Job Function: Technology Enterprise Strategy & Security Job Sub Function: Security & Controls Job Category: People Leader All Job Posting Locations: Pune... 
    Full time
    Local area

    8080-Johnson & Johnson Limited Legal Entity

    Pune
    16 days ago
  •  ...filings event transcripts expert calls news trade journals and clients own research content. The acquisition of Tegus by AlphaSense...  ...We are seeking an experienced Senior Business Applications Security Engineer to join our growing Corporate Technology team. This is... 
    Full time
    Remote job
    Flexible hours
    Shift work

    AlphaSense

    Pune
    22 days ago
  •  ...the world! Come work at a place where innovation and teamwork come together to support the most exciting missions in the world! As Security Signature Engineer, you will be part of a motivated engineering team that is responsible for the research, development, and delivery... 

    Qualys

    Pune
    more than 2 months ago
  •  ...Are you ready to take the lead in cutting-edge security engineering projects? We are looking for a seasoned professional with deep Saviynt experience, a strong background in cyber security, and a genuine passion for driving innovation in our growing security practice.... 
    Full time
    Hybrid work

    The Missing Link

    Pune
    29 days ago
  •  ...Pentester Security Engineer Context: The position is within the Michelin CERT team (Computer Emergency Response Team) the cyber defense team of the Michelin Group. Its three missions are: - Prevent and anticipate threats prepare for cyber crises - Detect threats vulnerabilities... 
    Full time

    Michelin

    Pune
    19 days ago
  •  ...software patches and configuration changes to be applied to varied software, middleware and hardware Provide assessment including security, system, and business impact of vulnerabilities Must be able to think ahead to avoid business outages based on the lab results... 
    Remote job
    Full time
    Shift work

    Qualys

    Pune
    more than 2 months ago
  •  ...Description Network Security II Engineer II (Enterprise IT Manufacturing/OT) Platforms: Palo Alto NGFW (Strata) Zscaler (ZIA/ZPA) F5 BIG-IP WAF (ASM/AWAF) ServiceNow Shift: Flexible AMER EMEA or APAC time zones Role Summary Support day-to-day network security... 
    Full time
    Internship
    Flexible hours

    Vertiv Group

    Pune
    19 days ago
  •  ...Description Job Title: Network Security Engineer II Location: Onsite Role Summary Were seeking a Senior Network Security Engineer to enhance our global security posture focusing mainly on Palo Alto Zscaler WAF IoT/OT security and zero-trust architecture. You will... 
    Full time
    Hybrid work
    Remote job

    Vertiv Group

    Pune
    a month ago
  •  ...you join us! Job Description Job Description Senior PAM Security Engineer Job Location – Pune / Bangalore Job Summary:...  ...lifecycle and CI/CD pipelines. Conduct security assessments, penetration testing, and remediation planning for identity and access management... 
    Hybrid work
    Work at office
    Local area
    Monday to Thursday

    Kalypso: A Rockwell Automation Business

    Pune
    more than 2 months ago
  •  ...come together to support the most exciting missions in the world! Overview: We are seeking a highly skilled and experienced Senior Security Engineer to join our team. As a Senior Security Engineer, you will be responsible for designing, implementing, and maintaining security... 
    Remote job
    For contractors

    Qualys

    Pune
    more than 2 months ago
  •  ...Role Summary The Security Engineer will design support and enhance identity and access services across Active Directory Microsoft Entra and enterprise applications. This role requires strong technical depth advanced troubleshooting ability automation expertise and the capability... 
    Full time

    Harris

    Pune
    a month ago
  • Job Description :We're on the hunt for a talented Senior Product Security Cybersecurity Engineer to elevate our Product Security team. In...  ...-depth security testing, including vulnerability assessments, penetration testing, and evaluations mandated by OEMs like Airbus and... 
    Shift work

    Antal International

    Pune
    13 days ago
  •  ...Public Cloud Security Engineer Vulnerability & Exposure Management (MultiCloud) This is a senior technical leadership role at the intersection...  ...management tools SIEM and centralised logging platforms Endpoint and workload protection technologies (EDR/XDR) Packet capture... 
    Full time
    Shift work

    NewVison

    Pune
    12 days ago
  •  ..., testing, deployment and delivery. Conducts performance, load, security and service virtualization testing. What Part Will You Play?...  ...Acts as a single point of contact for assigned moderately complex client projects with regard to test engineering activities. Coordinates... 
    Full time
    Worldwide

    Columbus, GA | Move to Meaningful

    Pune
    more than 2 months ago
  •  ...Senior Engineer Cyber  Product Security NielsenIQ is maturing its Application Security programs and is recruiting an Application Security Engineer who will be responsible for supporting the rollout of DevSecOps capabilities and practises across all geographies and business... 
    Full time
    Local area
    Flexible hours

    NielsenIQ

    Pune
    29 days ago
  • Role : Network Engineer L3 Palo Alto Security SpecialistSenior Level8+ Years ExperienceCCNP CertifiedDepartment : Information Technology / Network OperationsRole Level : L3 Senior Network EngineerExperience : 8+ Years (Networking), 4+ Years (Palo Alto NGFW)Certification : CCNP... 
    Full time
    Hybrid work
    Remote job
    Flexible hours

    Basebiz Private Limited

    Pune
    16 days ago
  •  ...integration testing deployment and delivery. Conducts performance load security and service virtualization testing. What Part Will You Play...  ...as a single point of contact for assigned moderately complex client projects with regard to test engineering activities. Coordinates... 
    Full time
    Worldwide

    Global Payment Holding Company

    Pune
    12 days ago
  •  ...affordable data connectivity in over 190 countries. Nomad is available as an iOS or Android app or via getnomad.app. Overview: As Security Engineer on the Infrastructure Team at LotusFlare you will be responsible to drive the overall IT security standards across our cloud... 
    Work at office
    Worldwide

    LotusFlare

    Pune
    more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Penetration Tester, Security Testing. Be the first to apply!