Penetration Tester
Posted Updated
We are seeking an experienced and highly technical Senior Cybersecurity Specialist to lead and execute comprehensive security assessments across industrial (OT/ICS), IoT, and automotive domains. You will drive hands-on penetration testing (VAPT), technical conformity assessments, threat modeling, and code reviews, while acting as a subject matter expert for client engagements, regulatory compliance, and team growth.
Key Responsibilities:
- Conduct comprehensive vulnerability assessments and penetration testing of networks, web/mobile applications, cloud environments, and specialized OT/ICS components (e.g., PLCs, SCADA, IoT, IIoT devices).
- Perform cybersecurity testing for automotive vehicles, including VAPT of ECUs and in-vehicle networks.
- Threat Modeling & Code Review: Conduct threat modeling, source code reviews for control flow/security flaws, and evaluate risk assessments to identify technical gaps.
- Develop, refine, and maintain audit-ready cybersecurity testing methodologies, procedures, and VAPT documentation.
- Lead cybersecurity assessments (e.g. VAPT, code review, threat modelling) across IIoT, OT, and ICS products and systems
- Deep Architectural Knowledge: Strong understanding of component and system architectures across both IT and OT environments, including common operating systems (Windows, Linux) and their respective security features.
- Network & Industrial Protocols: Strong grasp of network protocols and typical industrial communication protocols (e.g., Modbus, Profinet, OPC, DNP3.0, CAN).
Education & Experience:
- Bachelor’s degree in computer science, Information Security, Computer/Information Engineering, or a related technical field.
- 8-15+ years of overall cybersecurity experience, featuring a minimum of 5–8 years of dedicated security testing on industrial control systems (ICS), IoT, IIoT, or automotive product environments.
- Standards, Frameworks & Compliance
- Industrial & General OT Standards: Practical application of ISA/IEC 62443, NIST 800-82, NERC-CIP, MITRE ATT&CK, and NIST CSF.
- Specialized & Maritime Standards: Proficiency in developing VAPT methodologies specifically aligned with IEC 61162-460:2024 (maritime navigation and radiocommunication equipment) and ISO/IEC 27001.
- Automotive Standards: Strong compliance and threat modeling expertise aligned with ISO/SAE 21434.
- Regulatory & Conformity Frameworks: Familiarity with global regulations and assessment methodologies (e.g., CRA, RED, NIST SP 800-115, PTES, ISSAF, IEC 61508, NIST 800-53 CA-8)
- Industry Tools: High proficiency with standard penetration testing tools and frameworks (e.g., Nessus, Burp Suite, Nmap, and other ethical hacking utilities).
- Possession of at least one (or more) professional certification is highly advantageous:
- Offensive/Testing: OSCP, CREST, GPEN, CEH
- Audit/Management: CISA, CISM, CISSP, ISA/IEC 62443 Certified Specialist
- Exceptional verbal and written communication skills; ability to translate complex technical findings, risks, and recommended mitigations into clear reports for both technical teams and non-technical stakeholders.