Penetration Testing Engineer
Client: Arj Global’s Client
Location: Bengaluru, Hybrid / Onsite (as required)
Background
Arj Global’s client is seeking an experienced Penetration Testing Consultant to support security testing activities across applications, infrastructure, cloud, and SAP environments.
This role is critical in proactively identifying security vulnerabilities, simulating real-world attack scenarios, and ensuring remediation actions are addressed in line with the client’s cyber security standards and overall risk posture.
The consultant must have strong experience working within structured penetration testing methodologies and complex enterprise environments.
Scope of Services
The consultant will:
- Plan, execute, and report penetration tests and security assessments across:
- Web applications
- APIs
- Cloud services
- Infrastructure environments
- SAP systems
- Engage with stakeholders to:
- Define testing scope and objectives
- Align testing with threat-based scenarios
- Validate vulnerabilities and assess risk severity
- Provide:
- Clear, structured, and actionable remediation recommendations
- Technical and executive-level reports
- Risk prioritisation aligned to business impact
- Support:
- Re-testing and validation of remediated vulnerabilities
- Risk closure follow-ups
- Collaboration with Cyber, Digital, Infrastructure, and SAP teams
Key Responsibilities
- Conduct structured penetration testing using industry-recognised methodologies
- Identify, validate, and document vulnerabilities
- Map findings against recognised frameworks (e.g., OWASP, MITRE)
- Provide risk ratings and remediation guidance
- Present findings to both technical teams and senior stakeholders
- Contribute to continuous improvement of security testing processes
Requirements
Essential Skills & Experience
- Proven experience as a Penetration Tester / Offensive Security Consultant
- Strong hands-on experience in:
- Application penetration testing
- Infrastructure penetration testing
- Cloud security testing
- Solid understanding of:
- OWASP Top 10
- MITRE ATT&CK
- Industry-standard testing methodologies
- Ability to produce high-quality technical and executive-level reports
- Strong stakeholder communication skills (technical & non-technical audiences)
Most Critical Requirements
- Proven hands-on penetration testing experience
- Ability to produce clear, actionable findings and reports
- Strong knowledge of security standards and frameworks

