Sign up to access all features of our service
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Penetration Tester, Security Testing

Qualys

Pune
  • Remote job

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Job Description:
We are seeking a skilled Penetration Tester to assess and enhance the security of our cross-platform executable Qualys Cloud Agent.
This agent is responsible for system monitoring, data collection, and secure communication with a cloud platform.
Operating across Unix, Windows, and macOS environments, the agent plays a critical role in our security and compliance solutions.
The ideal candidate will uncover vulnerabilities, simulate attack scenarios, and work with our teams to fortify the system against threats.
Key Responsibilities:
Cross-Platform Agent Testing:
Conduct comprehensive security testing of the executable agent, ensuring robust functionality across Unix/Linux, Windows, and macOS platforms.
Identify and exploit vulnerabilities in the agent’s runtime behavior, system interactions, and interprocess communications.
Test agent privilege management and evaluate risks of escalation or exploitation.
Data Collection and Handling:
Analyze the agent’s data collection mechanisms to ensure data privacy and integrity.
Validate proper implementation of sensitive data redaction and secure storage practices.
Communication Security:
Test the agent’s secure communication mechanisms with the cloud server, focusing on:
Encryption (TLS/SSL, public key cryptography).
Authentication and session management.
Mitigation of threats like MITM, replay attacks, and DNS spoofing.

Reverse Engineering and Exploitation:
Perform binary analysis to identify vulnerabilities in the agent's implementation.
Reverse engineer agent components to assess the effectiveness of tamper-proofing mechanisms and embedded security features.
Simulate advanced threat scenarios, including code injection and runtime manipulation.
System Security Evaluations:
Assess the agent’s impact on host system security, ensuring it does not inadvertently introduce risks (e.g., open ports, exploitable configurations).
Evaluate installation, update, and self-defense mechanisms for tamper resistance and exploitation risks.
Reporting and Remediation:
Provide detailed vulnerability reports with proof of concept (PoC), risk impact assessments, and actionable remediation steps.
Collaborate with development team to address vulnerabilities and validate fixes
Contribute to improving secure development practices and robust agent design.
Required Qualifications:
Technical Expertise:
In-depth knowledge of penetration testing methodologies for executable agents, system processes, and OS-specific security models (Windows, Unix/Linux, macOS).
Proficiency in network security and cryptographic protocol testing.
Strong background in reverse engineering tools and techniques
Tools & Scripting:
Scripting skills in Python, Bash, PowerShell, for creating custom tests.
Hands on experience with proxy solutions ex Burp or Fiddler
Experience:
Proven track record of assessing software agents or similar system monitoring tools.
Familiarity with common vulnerabilities, including CVEs related to agent-based applications.
Experience working with security tools or platforms similar to Qualys Agent.
Certifications (Preferred):
OSCP, OSWE, CEH, GPEN, or equivalent cybersecurity certifications.
Relevant cloud certifications such as AWS Security Specialty, Azure Security Engineer Associate.
Preferred Qualifications:
Hands-on experience with agent technologies similar to Qualys Cloud Agent.
Familiarity with cloud architecture, APIs, and integration points.
Knowledge of secure coding practices and defensive programming.
Experience with CI/CD pipeline security.

Vacancy posted more than 2 months ago
Similar jobs that could be interesting for youBased on the Penetration Tester, Security Testing in Pune vacancy
  •  ...Skills (Foundational Exposure/Knowledge) Basic understanding of endpoint protection concepts (antivirus, EDR, device compliance)....  ...Understanding of SIEM concepts or log analysis. Broader knowledge of security frameworks (CIS, NIST) is beneficial but not required.... 
    Suggested

    InfoVision Inc.

    Pune
    15 days ago
  •  ...Excellence, Balewadi, Pune, Maharashtra 411045 Job Title: Security Engineer (Penetration Tester) Job Type: Full-time Reports To: Security Architect...  ...ideal candidate will be responsible for firewall and endpoint security, WAF implementation, VAPT, fraud investigation,... 
    Suggested
    Full time
    Hybrid work
    Work at office

    ISA

    Pune
    19 days ago
  •  ...Lead Engineer / Endpoint Security Engineering, VP Position Overview Job Title: Lead Engineer / Endpoint Security Engineering, VP Location: Pune, India Role Description As a Lead Engineer, you will be responsible for driving endpoint security engineering... 
    Suggested
    Flexible hours

    Deutsche Bank

    Pune
    13 days ago
  •  ...vulnerability assessment and penetration testing tools such as Nessus,...  ...understanding of networking concepts and security engineering principles...  ...) or GPEN (GIAC Penetration Tester) Strong technical writing...  ...identify security weaknesses in client systems and infrastructure... 
    Suggested

    PKF Algosmic Pvt Ltd

    Pune
    22 days ago
  •  ...solution! Join us to make your contribution.   AGCO is looking to hire candidates for the position of Sr. Penetration Tester.   At AGCO, the Product Security team is at the forefront of securing our next-generation agricultural machinery. Our core mission is to... 
    Suggested
    Worldwide
    Flexible hours

    AGCO

    Pune
    21 days ago
  •  ...Fortinet is a worldwide provider of network security appliances and the market leader in...  ...software, intrusion prevention systems and endpoint security components. Fortinet is headquartered...  ...to communicate effectively with various clients with the ability to explain and elaborate... 
    Hybrid work

    Fortinet

    Pune
    14 days ago
  • Rs 1 - 3 lakhs p.a.

     ...Provide expert technical support for a wide range of security products and solutions to internal teams and/or clients. Firewall Management: Install, configure,...  ...hands-on experience in F5 and Citrix Netscaler. Endpoint Security: Diagnose and resolve issues related to endpoint... 

    Geetha Technology Solutions

    Pune
    a month ago
  •  ...consumers, worldwide. ZSers drive impact by bringing a client-first mentality to each and every engagement. We...  ...life-changing impact to ZS. Associate Consultant - Security Architecture & Engineering (Endpoint Security) The Security Architecture & Engineering Associate... 
    Full time
    No agency
    Hybrid work
    Local area
    Work from home
    Worldwide
    Flexible hours
    Afternoon shift

    ZS Associates

    Pune
    14 days ago
  •  ...in IBM Consulting is built on long-term client relationships and close collaboration worldwide...  ...Integrate threat intelligence into security monitoring systems to enhance proactive threat...  ..., zoning, integration aspects, API, endpoint security, data security, compliance, and... 
    Long term contract
    Hybrid work
    Worldwide

    IBM

    Pune
    5 days ago
  •  ...Join us as a Penetration Tester in Barclays, responsible for supporting the successful delivery of...  ...Infrastructure. APIs. Mobile Apps. Thick clients. MCPs/AI Agents/LLMs. Cloud environments. Understanding of the security mechanisms associated with Applications,... 
    Permanent employment

    Barclays

    Pune
    23 days ago
  •  ...Job Title : Email Security Administrator - Level 2 Designation: Infrastructure Security...  ...Diagnose and resolve email delivery issues, client connectivity problems, and other email-...  ...years of experience in email operations, endpoint security, and device management. ~... 
    Full time
    Work at office
    Shift work

    Gruve

    Pune
    3 days ago
  •  ...Summary of This Role Install, configure, maintain, support, and secure the organization's network communications, including LANs and/or...  ...in advanced Network project tasks with internal and external clients Provides mentorship to entry/lower level team members Assists... 
    Full time
    Local area
    Worldwide

    Global Payments

    Pune
    14 days ago
  •  ...75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation...  ..., with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our... 
    Hybrid work
    Work at office
    Remote job
    Flexible hours

    NTT Data

    Pune
    2 days ago
  •  ...management trading system, which allows clients to completely control and customize their...  ...Vulnerability Management Engineer to strengthen our Security Operations function. You will own the end...  ...remediation coordination—across servers, endpoints, cloud workloads, and network... 
    Permanent employment
    Full time

    FlexTrade

    Pune
    17 days ago
  •  ...Technologies is a leading technology integrator specializing in helping clients reimagine operating models, enhance competitiveness, optimize...  ...of the future. We are looking forward to hireSAP Security Professionals in the following areas : Job description... 
    Flexible hours

    Yash Technologies Private Limited

    Pune
    14 days ago
  • Rs 7.87 - 13 lakhs p.a.

     ...Technologies is a leading technology integrator specializing in helping clients reimagine operating models, enhance competitiveness, optimize...  ...of the future. We are looking forward to hire SAP Security Professionals in the following areas : Job Description Experience... 
    Flexible hours

    YASH Technologies

    Pune
    3 days ago
  •  ...Information Risk Management LLP (PIRM) is a global player in Information Security, Cybersecurity, Compliance, and Risk Management solutions with a...  ..., the USA, Asia, Europe, and the Middle East. Serving over 150 clients worldwide, PIRM operates a dedicated managed security testing... 
    Full time
    Worldwide

    Presidio Information Risk Management LLP

    Pune
    10 days ago
  •  ...Job Title: Cybersecurity Analyst / Security Operations Analyst Experience: 4-8 years Summary: Detail-oriented and proactive Cybersecurity...  ...Sentinel , Nessus , Sophos , and Microsoft Defender for Endpoint . Adept at investigating phishing threats, building insightful... 

    Fulcrum Digital Inc

    Pune
    14 days ago
  •  ...Join us as a “Senior Penetration Tester" at Barclays, where you'll spearhead the evolution of our...  ...Web applications, APIs, mobile & Thick Clients Infrastructure and networks Virtualization...  ...and Kubernetes) Understanding of the security mechanisms associated with Applications... 
    Long term contract
    Temporary work

    Barclays

    Pune
    7 days ago
  •  ...JOB RESPONSIBILITIES: • Deliver offensive security services in at least two of the following...  ...application, web application and wireless penetration testing and related technical security assessments. • Collaborate with clients, project management, and engagement... 

    CheckRed

    Pune
    16 days ago
  •  ...worldwide. ZSers drive impact by bringing a client-first mentality to each and every...  ...to ZS. What you'll do: Perform security assessments (including some ethical hacking...  ...in information security, as an analyst, penetration tester or operator of security systems. ~... 
    Full time
    No agency
    Hybrid work
    Local area
    Remote job
    Work from home
    Worldwide
    Flexible hours
    2 days week
    3 days week

    ZS Associates

    Pune
    14 days ago
  •  ...background support. That's what we do. And we do it for private clients, institutions, and corporations around the world. We have about...  ...is a global organization within the Tech Information Security Office. Our services focus on cybersecurity monitoring, incident... 
    Work at office

    Luxoft India

    Pune
    15 days ago
  •  ...About The Role The Senior Security Engineer role is a highly technical position responsible for strengthening the organization's cybersecurity posture through robust infrastructure, endpoint, and cyber security measures. The role requires strong expertise in Zero Trust implementation... 
    Hybrid work
    Work at office
    Remote job

    PubMatic

    Pune
    10 days ago
  • Rs 3 - 6 lakhs p.a.

     ...Must have 6+ years of SAP Security and/or GRC support and implementation experience Hands-on experience on SAP Security and Authorizations...  ...on building a custom ruleset based on the requirement from the client. Should have experience in managing complex workflows and... 

    Argano Software

    Pune
    3 days ago
  • Rs 12 - 28 lakhs p.a.

     ...Define and maintain enterprise security architecture standards and reference architectures across on-premises, cloud infrastructure, SaaS...  ...custom applications. Design secure solutions covering network, endpoint, cloud security, identity and access management, privileged access... 
    Contract work

    Aziro

    Pune
    2 days ago
  •  ...Job Description The Role: The Senior Security Engineer is a critical role within Security Engineering & Cyber Security, responsible...  ...Provide technical oversight of enterprise security toolsets spanning endpoint, server, identity, email, network, cloud, and detection &... 
    Long term contract
    Full time
    Hybrid work

    Apex Group Ltd (India Branch)

    Pune
    13 hours ago
  •  ...About the role: We are seeking a hands-on Security & Compliance Lead to own and execute end-to-end security audits and compliance initiatives...  ...(e.g., VRA, security checklists) required by new BFSI clients. Analyse and complete detailed cloud infrastructure security... 

    PeopleGene

    Pune
    3 days ago
  • Rs 5 - 8 lakhs p.a.

     ...We are seeking an experienced Microsoft Security Professional to safeguard and optimize the organization's digital environment. This role...  ...Deploy and manage security solutions: Microsoft Defender for Cloud, Endpoint, Identity, Office 365, Cloud Apps, and Microsoft Sentinel.... 
    Hybrid work
    Work at office

    Han Digital Solution

    Pune
    a month ago
  • Obsessed with security Are you looking for a new opportunity to channel your security expertise into building, integrating, and automating...  ...build, integrate and automate security controls from cloud to endpoint. Act as a subject matter expert while partnering with Corporate... 

    Rapid7

    Pune
    16 days ago
  •  ...to contribute to the development, deployment, and integration of security tooling across our infrastructure. This role is instrumental in...  ...Response, secrets management, application security scanning systems, endpoint protection systems and others. Develop and maintain custom... 
    Contract work
    Local area

    OpenGov Inc.

    Pune
    15 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Penetration Tester, Security Testing. Be the first to apply!