Sign up to access all features of our service
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Penetration Tester, Security Testing

Qualys

Pune
  • Remote job

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Job Description:
We are seeking a skilled Penetration Tester to assess and enhance the security of our cross-platform executable Qualys Cloud Agent.
This agent is responsible for system monitoring, data collection, and secure communication with a cloud platform.
Operating across Unix, Windows, and macOS environments, the agent plays a critical role in our security and compliance solutions.
The ideal candidate will uncover vulnerabilities, simulate attack scenarios, and work with our teams to fortify the system against threats.
Key Responsibilities:
Cross-Platform Agent Testing:
Conduct comprehensive security testing of the executable agent, ensuring robust functionality across Unix/Linux, Windows, and macOS platforms.
Identify and exploit vulnerabilities in the agent’s runtime behavior, system interactions, and interprocess communications.
Test agent privilege management and evaluate risks of escalation or exploitation.
Data Collection and Handling:
Analyze the agent’s data collection mechanisms to ensure data privacy and integrity.
Validate proper implementation of sensitive data redaction and secure storage practices.
Communication Security:
Test the agent’s secure communication mechanisms with the cloud server, focusing on:
Encryption (TLS/SSL, public key cryptography).
Authentication and session management.
Mitigation of threats like MITM, replay attacks, and DNS spoofing.

Reverse Engineering and Exploitation:
Perform binary analysis to identify vulnerabilities in the agent's implementation.
Reverse engineer agent components to assess the effectiveness of tamper-proofing mechanisms and embedded security features.
Simulate advanced threat scenarios, including code injection and runtime manipulation.
System Security Evaluations:
Assess the agent’s impact on host system security, ensuring it does not inadvertently introduce risks (e.g., open ports, exploitable configurations).
Evaluate installation, update, and self-defense mechanisms for tamper resistance and exploitation risks.
Reporting and Remediation:
Provide detailed vulnerability reports with proof of concept (PoC), risk impact assessments, and actionable remediation steps.
Collaborate with development team to address vulnerabilities and validate fixes
Contribute to improving secure development practices and robust agent design.
Required Qualifications:
Technical Expertise:
In-depth knowledge of penetration testing methodologies for executable agents, system processes, and OS-specific security models (Windows, Unix/Linux, macOS).
Proficiency in network security and cryptographic protocol testing.
Strong background in reverse engineering tools and techniques
Tools & Scripting:
Scripting skills in Python, Bash, PowerShell, for creating custom tests.
Hands on experience with proxy solutions ex Burp or Fiddler
Experience:
Proven track record of assessing software agents or similar system monitoring tools.
Familiarity with common vulnerabilities, including CVEs related to agent-based applications.
Experience working with security tools or platforms similar to Qualys Agent.
Certifications (Preferred):
OSCP, OSWE, CEH, GPEN, or equivalent cybersecurity certifications.
Relevant cloud certifications such as AWS Security Specialty, Azure Security Engineer Associate.
Preferred Qualifications:
Hands-on experience with agent technologies similar to Qualys Cloud Agent.
Familiarity with cloud architecture, APIs, and integration points.
Knowledge of secure coding practices and defensive programming.
Experience with CI/CD pipeline security.

Vacancy posted more than 2 months ago
Similar jobs that could be interesting for youBased on the Penetration Tester, Security Testing in Pune vacancy
  •  ...Job Title L2 Security Expert– Penetration Testing (Application & Network) Experience 10 to 14 years...  ...The L2 Security Engineer (penetration tester) will be responsible for performing...  ...applications, mobile applications, rich client applications, and network... 
    Suggested

    Agile Technology Solutions - Your Technology Partner

    Pune
    2 days ago
  •  ...Position Overview Job Title: Lead Engineer / Endpoint Security Engineering, VP Location: Pune, India Role Description As a Lead Engineer, you will be responsible for driving endpoint security engineering initiatives across the bank. You will design, implement... 
    Suggested
    Flexible hours

    Deutsche Bank

    Pune
    2 days ago
  •  ...vulnerability assessment and penetration testing tools such as Nessus,...  ...understanding of networking concepts and security engineering principles...  ...) or GPEN (GIAC Penetration Tester) Strong technical writing...  ...identify security weaknesses in client systems and infrastructure... 
    Suggested

    PKF Algosmic Pvt Ltd

    Pune
    14 days ago
  •  ...Job Description Job Title: Endpoint Security Engineer (Intune & Defender) Location: Pune Department: Infra Security Experience: 5 to 7 years Reporting To: Technical Lead Manager Joining: Within a week or two Job Summary We are seeking a skilled and proactive... 
    Suggested

    AlifCloud IT Consulting Pvt. Ltd.

    Pune
    2 days ago
  •  ...solution! Join us to make your contribution. AGCO is looking to hire candidates for the position of  Sr. Penetration Tester. At AGCO, the Product Security team is at the forefront of securing our next-generation agricultural machinery. Our core mission is to design... 
    Suggested
    Worldwide
    Flexible hours

    AGCO

    Pune
    18 hours ago
  •  ...Provide expert technical support for a wide range of security products and solutions to internal teams and/or clients. Firewall Management: Install, configure,...  ...hands-on experience in F5 and Citrix Netscaler. Endpoint Security: Diagnose and resolve issues related to endpoint... 

    Geetha Technology Solutions

    Pune
    a month ago
  •  ...Fortinet is a worldwide provider of network security appliances and the market leader in...  ...software, intrusion prevention systems and endpoint security components. Fortinet is headquartered...  ...to communicate effectively with various clients with the ability to explain and elaborate... 
    Hybrid work

    Fortinet

    Pune
    1 day ago
  •  ...Technologies is a leading technology integrator specializing in helping clients reimagine operating models, enhance competitiveness, optimize...  ...of the future. We are looking forward to hireSAP Security Professionals in the following areas : Job description... 
    Flexible hours

    Yash Technologies Private Limited

    Pune
    2 days ago
  •  ...Technologies is a leading technology integrator specializing in helping clients reimagine operating models, enhance competitiveness, optimize...  ...of the future. We are looking forward to hire SAP Security Professionals in the following areas : Job Description Experience... 
    Flexible hours

    YASH Technologies

    Pune
    1 day ago
  •  ...In this role, you'll work in one of our IBM Consulting Client Innovation Centers (Delivery Centers), where we deliver deep technical and...  ...term engagement in an advisory capacity. As an Application Security Consultants, the person should leverage the technical expertise... 
    Long term contract
    Full time

    IBM

    Pune
    a month ago
  • Description :- Review and govern the overall security architecture of the products. - Review Penetration test deliverable and mentor penetration test engineers to ensure...  ...test for new products (Web Applications, Thick Client, IIoT Solutions, Cloud Solutions and Containers). -... 
    Flexible hours

    Emerson (Emerson)(2252)

    Pune
    26 days ago
  •  ...Pune, Maharashtra 411045 Job Title: Security Engineer Job Type: Full-time Reports...  ...will be responsible for firewall and endpoint security, WAF implementation, VAPT, fraud...  ...Perform Vulnerability Assessments & Penetration Testing (VAPT) on infrastructure, applications... 
    Full time
    Hybrid work
    Work at office

    ISA

    Pune
    2 days ago
  •  ...excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it...  ...can grow, belong and thrive. Your day at NTT DATA The Security Remote Field Service Engineer (L2) is a developing engineering... 
    Remote job

    NTT DATA

    Pune
    15 hours ago
  •  ...background support. That's what we do. And we do it for private clients, institutions, and corporations around the world. We have about...  ...is a global organization within the Tech Information Security Office. Our services focus on cybersecurity monitoring, incident... 
    Work at office

    Luxoft

    Pune
    21 days ago
  •  ...to contribute to the development, deployment, and integration of security tooling across our infrastructure. This role is instrumental in...  ...Response, secrets management, application security scanning systems, endpoint protection systems and others. Develop and maintain custom... 
    Contract work
    Local area

    OpenGov Inc.

    Pune
    2 days ago
  •  ...team in Cambridge. You will be working on the HP Wolf Security Cloud Service - a web-based platform to manage our security...  ...provides security policy and software updates for the endpoint security product installed on the client PCs. It also receives status, events and threat data... 
    Hybrid work
    Work at office

    HP

    Pune
    13 days ago
  •  ...the subject matter expert for supported security technologies and during escalations; provides...  ...where applicable.- Evaluates ISA/Clients standards, security controls, and industry...  ...attack techniques.- Regularly undertakes penetration testing across the network and application... 

    ISA

    Pune
    24 days ago
  •  ...We are seeking an experienced Microsoft Security Professional to safeguard and optimize the organization's digital environment. This role...  ...Deploy and manage security solutions: Microsoft Defender for Cloud, Endpoint, Identity, Office 365, Cloud Apps, and Microsoft Sentinel.... 
    Hybrid work
    Work at office

    Han Digital Solution

    Pune
    a month ago
  • Obsessed with security Are you looking for a new opportunity to channel your security expertise into building, integrating, and automating...  ...build, integrate and automate security controls from cloud to endpoint. Act as a subject matter expert while partnering with Corporate... 

    Rapid7

    Pune
    2 days ago
  •  ...equivalent practical experience. ~3 years of experience in information security or IT risk management with a focus on security, performance and...  ...other team members to produce prioritized results aligned to client needs and risk profile. Provide guidance on building or... 

    Google

    Pune
    1 day ago
  •  ...JOB RESPONSIBILITIES Deliver offensive security services in at least two of the following areas...  ...application, web application and wireless penetration testing and related technical security assessments. Collaborate with clients, project management, and engagement leaders... 

    Clearwater

    Pune
    5 days ago
  •  ...Deutsche Bank's cryptography engineering and solution department is part of the Chief Security Office (CSO) which determine the cryptography strategy for the bank and support business partners in all questions around crypto, including audit and regulatory support. We are currently... 
    Work at office
    Flexible hours

    Dws Investment

    Pune
    a month ago
  • ~ Job Title: SMTP Security Architect About Us Capco a Wipro company is a global technology and management consulting firm. Awarded with...  ...With our presence across 32 cities across globe we support 100 clients acrossbanking financial and Energy sectors. We are recognized for... 
    Full time
    Hybrid work
    Local area
    Shift work

    Capco

    Pune
    9 days ago
  •  ...people gives our teams an expanded perspective and the ability to find better solutions for our clients. Visa Sponsorship Available: No Job Summary The Network Security Senior Analyst will oversee and help safeguard the enterprise on-premises, cloud, and... 
    Long term contract
    Hybrid work
    Visa sponsorship
    Remote job

    Black & Veatch

    Pune
    2 days ago
  •  ...enable sustainable product investment and enhancements, to keep our clients at the cutting-edge of engineering, infrastructure and...  ...builds. Find out more at RIB Careers. Job Title: Product Security Engineer Location: India Job Type: Full-time Driven by... 
    Full time
    Local area
    Worldwide

    RIB Software

    Pune
    1 day ago
  •  ...composable, model-driven services that protect high-value assets with security, compliance, and control by design. Our mission is to...  ...model-driven technology is delivered reliably in complex, regulated client environments. You ensure projects are delivered on time, within... 
    Long term contract
    Full time
    Hybrid work

    XLINQ

    Pune
    4 days ago
  •  ...Responsibilities Pipeline Management: Maintain high-throughput streaming pipelines to ingest logs from various sources (Firewalls, Cloud, Endpoints) to a central destination. Log Normalization: Write parsers to convert raw, messy logs into standard schemas (e.g., OCSF or ECS)... 

    Clearwater

    Pune
    5 days ago
  •  ...passionate about financial inclusion, investor transparency, and secure digital experiences. As we scale, security remains central to...  .... Evaluate and onboard security tools (e.g., SIEM, WAF, DLP, endpoint security). Build a security-first culture through training and... 

    InCred Money

    Pune
    2 days ago
  •  ...together to support the most exciting missions in the world! Security Solutions Analyst/Security Solutions Architect Come work at a...  ...application security, and threat detection Understanding of managing endpoints, servers, virtual infrastructure along with deployments of... 
    Local area
    US shift

    Qualys

    Pune
    2 days ago
  • Job Description Job Summary: As a Security Operations Engineer, you will be an integral part of Qualys SOC (Security Operation Center) and...  ...intrusion detection/prevention systems, firewalls, and endpoint protection solutions. Participate in the configuration and fine-... 

    Qualys

    Pune
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Penetration Tester, Security Testing. Be the first to apply!