TymblHub

© 2026 TymblHub

Penetration Tester

JAGGAER
Posted on

Experience
3 - 5 yrs
Job Location
Hyderabad, India
Vacancy
1
Designation
Penetration Tester
Job Type
Not specified

Job Description

Job Summary

Product Security Engineer AI Application Security | Cyber Architecture Defense

Penetration Tester Offensive Security | Cyber Architecture Defense

Reporting to the Director of Cyber Architecture Defense, we are seeking a Penetration Tester to lead hands-on offensive security testing across the full portfolio of JAGGAER applications, platforms, and infrastructure - including our AI-powered and agentic capabilities. This role works closely with our Product Security Engineer and development teams to identify exploitable vulnerabilities before attackers do, through internal and external network testing, web application and API testing, cloud configuration testing, and adversarial testing of AI/ML-integrated features. Were looking for someone who goes beyond checklist-driven testing - who thinks like a real adversary, develops novel attack techniques tailored to our specific applications, and builds the automation and tooling - including AI-assisted testing workflows - needed to scale that creativity across a large and growing product portfolio. You will plan and execute engagements independently, clearly communicate risk and business impact to both technical and non-technical stakeholders, and help validate remediation efforts across the SDLC.

Responsibilities

  • Plan, scope, and execute penetration tests across the full portfolio of JAGGAER applications, platforms, APIs, internal and external networks, and cloud environments (GCP, AWS, Azure), applying frameworks such as the OWASP Top 10, OWASP API Security Top 10, and MITRE ATTCK - including AI-powered and agentic features, where risks such as prompt injection, insecure output handling, and excessive agency are assessed against the OWASP LLM Top 10 and OWASP Agentic AI Top 10.
  • Go beyond standard methodology and known CVEs - think creatively about how JAGGAERs specific applications, integrations, and business logic could be abused, and develop novel, custom attack techniques and proof-of-concept exploits tailored to those scenarios.
  • Build automation and tooling to scale testing coverage and repeatability across a large, growing, and constantly-changing application and platform portfolio, rather than relying solely on manual, point-in-time assessments.
  • Embed AI-assisted techniques into the testing workflow itself - using LLM-driven and vibe testing approaches to accelerate reconnaissance, test case and payload generation, fuzzing, and triage - while validating AI-generated results before acting on them.
  • Conduct authenticated and unauthenticated testing of multi-tenant SaaS environments, identifying cross-tenant and privilege-escalation risks.
  • Design and run red-team style exercises and attack simulations to validate detection and response capabilities in partnership with security operations.
  • Partner with the Product Security Engineer and development teams to translate findings into actionable, risk-prioritized remediation guidance, and retest to confirm fixes.
  • Support the Vulnerability Disclosure Program (VDP) by validating and reproducing externally reported findings and assessing real-world exploitability.
  • Assess software supply chain and dependency risk from an attackers perspective, including exploitability of vulnerable third-party and open-source components.
  • Coordinate and provide oversight of third-party penetration testing engagements, ensuring scope, quality, and findings meet internal and customer/compliance expectations.
  • Produce clear, well-evidenced reports for technical and executive audiences, including risk ratings, exploitation narratives, and remediation guidance.
  • Maintain test tooling, attack infrastructure, and internal methodologies, keeping pace with emerging attack techniques.
  • Serve as a security champion, promoting an attackers-eye-view of risk and offensive security awareness across engineering and product teams.
  • Maintain functional understanding of common compliance frameworks relevant to testing scope and cadence, including NIST 800-53, PCI DSS, SOC 2 Type II, and CSA CCM.

Requirements

What You Will Bring

  • Bachelors degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
  • 3+ years of hands-on experience performing penetration tests or red team engagements across web applications, networks, and cloud environments.
  • Proficient in at least one scripting or programming language (e.g., Python) for tooling, exploit development, and automation at scale.
  • Demonstrated ability to think beyond established methodology - chaining findings, abusing business logic, and developing original attack paths rather than relying only on known tools and signatures.
  • Comfort using AI-assisted and vibe testing workflows (e.g., LLM-driven test generation, fuzzing, or triage) to accelerate offensive testing, paired with the judgment to critically validate AI-generated output.
  • Strong understanding of web application, API, network, and cloud security across multi-cloud environments (GCP, AWS, Azure).
  • Familiarity with AI/LLM security concepts and agentic AI systems (e.g., prompt injection, model supply chain risk) is a strong plus, as testing scope spans the full JAGGAER application and platform portfolio, including AI-powered features.
  • Experience validating findings from a Vulnerability Disclosure Program (VDP) or bug bounty program is a plus.
  • Strong written and verbal communication skills, with the ability to translate technical findings into business risk for varied audiences.
  • Offensive Security Certification such as OSCP, GPEN, CEH, or similar hands-on offensive security certifications are a plus.
Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.