Penetration Test Engineer Product Cybersecurity

4 - 6 years

13 - 17 Lacs

Posted:19 hours ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

Summary:

We are looking for an experienced Embedded and Application Penetration Tester to join our Product Cybersecurity team. In this role, you will be responsible for conducting comprehensive security assessments of our products including embedded devices, web applications, thick-client applications, and mobile applications.

Experience & Qualifications:

  • Bachelor's degree in computer science, cybersecurity, or a related field
  • 4 - 6 years of experience in embedded/IoT system, web applications, AI models and network penetration testing.
  • Hands-on experience in embedded systems security testing including firmware security, secure configuration analysis, secure boot, physical port testing (USB, serial, CAN, wireless, etc.,)
  • Strong expertise in various penetration testing techniques and attack frameworks such as MITRE ATTCK, fuzz testing, brute force attacks, OWASP top 10 tests, and more
  • Hands-on experience with penetration testing tools including open-source tools, such as Metasploit and the Kali Linux tool set, Nessus, Qualys guard, nmap , Wireshark and Burp Suite etc.,
  • Demonstrate strong manual penetration testing skills and techniques are required besides automated tools and frameworks
  • Knowledge of the secure SDLC and vulnerability/risk lifecycle
  • Knowledge of common vulnerability frameworks such as CVSS, and OWASP top 10
  • Strong problem-solving and critical thinking skills
  • Certification in a relevant area such as OSCP, OSWP, GPEN, CPTC, or CPTE is highly desired
  • Excellent communication, reporting, and presentation skills
  • Ability to collaborate effectively as part of a global cross functional team, working independently with minimal supervision.

Responsibilities:

  • Conduct comprehensive security assessments of Wabtec products, including embedded devices, IoT devices, thick client, AI, mobile and web applications,
  • Use penetration testing and Red Team techniques to discover and exploit vulnerabilities
  • Create findings reports and communicate to stakeholders
  • Perform compliance testing of embedded systems with respect to IEC-62443-4-2 standards
  • Explore new ways to exploit devices applications
  • Provide guidance on vulnerability remediation to product teams
  • Recommend and implement improvements to testing processes and methodologies
  • Support PSIRT and Vulnerability Disclosure processes and activities
  • Promote security awareness through exploit demonstrations
  • Proactively perform threat hunting for any new vulnerabilities/risk associated with products and applications.
  • Be up to date with cybersecurity trends and share information on new exploits, vulnerabilities to the appropriate stakeholders .
  • Collaborate with cross-functional teams and stakeholders to identify and mitigate security risks.

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
Wabtec logo
Wabtec

Rail Transportation

Pittsburgh

RecommendedJobs for You

hyderabad, gurugram, bengaluru