Shieldbyte Infosec Pvt. Ltd.
Website:
shieldbyteinfosec.com
Job details:
Location : Mumbai (Onsite)
ShieldByte Infosec Pvt. Ltd. is a CERT-In empanelled auditor and a leading cybersecurity company in India, specializing in Cyber Security, Data Privacy, and Information Security consulting and compliance audits. The company supports global clients across more than 20 countries, providing tailored security solutions built on trust and confidence. ShieldByte focuses on delivering high-quality, customized services that not only meet but aim to exceed client requirements. The organization emphasizes integrity, strong partnerships, exceptional customer service, and community leadership, while fostering professional growth for its team members.
Role Description:
- Conduct manual and automated penetration testing across web applications, mobile apps (Android/iOS), APIs, networks (internal/external), cloud (AWS/Azure/GCP), and thick-client applications.
- Perform vulnerability assessments aligned to OWASP Top 10, SANS 25, WSTG, MITRE ATT&CK, PTES, and NIST.
- Exploit, validate, and document findings with clear risk ratings (CVSS) and actionable remediation guidance.
- Retest and verify closure of reported vulnerabilities.
- Execute adversary-simulation and social-engineering engagements (phishing, physical, pretexting).
- Perform lateral movement, privilege escalation, persistence, and command-and-control (C2) operations.
- Emulate real-world TTPs mapped to the MITRE ATT&CK framework.
- Bypass security controls (EDR/AV/WAF) and assess detection & response maturity (purple teaming).
- Perform secure code reviews and static analysis across languages (Java, .NET, Python, JavaScript, etc.).
- Integrate SAST tools into CI/CD pipelines and support DevSecOps / secure SDLC practices.
- Identify insecure coding patterns and guide developers on secure remediation.
- Produce detailed technical and executive-level assessment reports.
- Present findings to clients and support remediation discussions.
Qualifications
• 1–8 years of hands-on experience in VAPT, Red Teaming, and/or application security.
• Strong grasp of network, web, mobile, API, and cloud security fundamentals.
• Familiarity with tools such as Burp Suite, Nmap, Metasploit, Cobalt Strike, Nessus, BloodHound, Nuclei, Wireshark, and Checkmarx / Fortify / SonarQube / Semgrep.
• Scripting ability in Python, Bash, or PowerShell.
• Solid understanding of OWASP, MITRE ATT&CK, CVSS, and the secure SDLC.
• Strong report-writing and communication skills.
• Offensive Security: OSCP, OSEP, OSWE, OSWA, OSED
• Red Team: CRTP, CRTO, CRTE, CRTL
• Pentest / Web: CEH (Practical), eJPT, eWPT, eWPTX, eCPPT, GPEN, GWAPT, GXPN, CompTIA PenTest+
• Foundational / Senior: CompTIA Security+, CISSP, CISM (for senior candidates)
Click on Apply to know more.