×
Register Here to Apply for Jobs or Post Jobs. X

Security Engineer - OSCP

Job in 110006, Delhi, Delhi, India
Listing for: TAC Security
Full Time position
Listed on 2026-09-24
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Network Security
Job Description & How to Apply Below
Role Purpose
TAC Security is looking for a highly skilled  Security Engineer – OSCP Certified  with strong hands-on expertise in  penetration testing, vulnerability assessment, application security, network security, and offensive security .
The Security Engineer will be responsible for identifying, validating, and demonstrating security vulnerabilities across web applications, APIs, mobile applications, networks, cloud environments, and infrastructure. The role requires a strong offensive-security mindset, practical exploitation skills, and the ability to provide actionable remediation guidance to clients and internal teams.

Key Responsibilities
1. Vulnerability Assessment & Penetration Testing
Perform end-to-end  Vulnerability Assessment and Penetration Testing (VAPT)  across applications and infrastructure.
Conduct manual penetration testing rather than relying solely on automated scanning tools.
Identify, validate, exploit, and document security vulnerabilities.
Perform network and infrastructure penetration testing across internal and external environments.
Conduct security testing of web applications, APIs, mobile applications, and cloud-based environments.
Perform vulnerability verification and retesting after remediation.
Evaluate vulnerabilities based on technical severity, exploitability, and potential business impact.
2. Web Application & API Security
Perform advanced web application penetration testing aligned with  OWASP Top 10  and relevant testing methodologies.
Test for vulnerabilities including SQL Injection, XSS, SSRF, IDOR, authentication and authorization weaknesses, insecure deserialization, file-upload vulnerabilities, business-logic flaws, and security misconfigurations.
Conduct API security assessments covering REST and other API architectures.
Identify complex authorization, authentication, session-management, and business-logic vulnerabilities.
3. Network & Infrastructure Security
Conduct external and internal network penetration testing.
Perform network enumeration, service discovery, vulnerability analysis, exploitation, and privilege escalation.
Assess Windows and Linux environments for security weaknesses.
Conduct  Active Directory security assessments  and identify privilege-escalation and lateral-movement opportunities.
Evaluate firewall configurations, exposed services, network segmentation, and infrastructure security controls.
4. Offensive Security & Exploitation
Apply OSCP-level penetration-testing techniques in real-world environments.
Perform manual exploitation, privilege escalation, pivoting, lateral movement, and post-exploitation activities within approved scopes.
Develop or modify scripts and proof-of-concept exploits when required.
Use offensive-security techniques responsibly and strictly within authorized testing environments.
Maintain detailed evidence and attack paths throughout engagements.
5. Security Tools & Technologies
Hands-on experience with tools such as:
Burp Suite Professional
Nmap
Metasploit
Nessus
Kali Linux
Wireshark
Blood Hound
Impacket
SQLMap
Nikto
Gobuster/Ffuf
Hydra
John the Ripper/Hashcat
Candidates should understand the underlying techniques and be capable of performing manual validation rather than depending exclusively on tools.
6. Reporting & Remediation
Prepare detailed and professional penetration-testing reports containing vulnerability descriptions, severity, evidence, proof of concept, business impact, and remediation recommendations.
Assign severity using appropriate methodologies such as  CVSS .
Conduct technical walkthroughs with customers, developers, security teams, and management.
Work closely with engineering teams to explain vulnerabilities and recommend practical remediation.
Perform remediation validation and closure testing.
7. Research &…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary