Role overview:
- Performing hacker style pentests on our customer’s applications and managing the entire pentest using our one of a kind Pentest platform.
Carrying out VA/PT for web apps, mobile apps, Cloud infrastructure, SaaS apps, network devices, open-source projects etc.
Contributing towards building intelligence for our DAST scanner.
Interacting with clients over remediation calls.
Facilitating clients to map out the steps for fixing vulnerabilities.
Maintaining our vulnerability management system.
Requirements
OSCP or CREST certified
Strong understanding of OWASPs testing guidelines
3-5 years of professional experience in doing pentests on multiple assets including web apps, cloud infrastructure etc.
Comfortable in Black Box, WhiteBox testing with capability of finding business logic vulnerabilities
Experience directly interfacing with customers over calls & emails
Able to understand code in any one programming language
Good to have:
A few published CVE’s
A bug bounty/CTF experience
Benefits
- You’ll own your work from day one—no micromanaging, just trust and impact.
- Health Insurance cover for you and your spouse.
- You’ll join a team that’s scaling fast but still feels like a close-knit crew—think startup energy with global reach.
- You’ll be surrounded by curious minds, creative thinkers, and people who genuinely care (and yes, we do have a dedicated meme channel on slack).
- Dive deep into the captivating world of cybersecurity.
- And yes, get ready for some unforgettable workcations—think Chikmagalur & Jim Corbett. The previous one was at Wayanad, KL
Skills Required
- OSCP or CREST certification
- Strong understanding of OWASP testing guidelines
- 3–5 years of professional penetration testing experience across multiple asset types, including web applications and cloud infrastructure
- Experience with black-box and white-box testing, including identifying business logic vulnerabilities
- Experience interfacing directly with customers through calls and email
- Ability to understand code in at least one programming language
- Published CVEs
- Bug bounty or CTF experience
What We Do
Astra Security is a cybersecurity SaaS company headquartered in the United States and India. It provides an AI-powered continuous penetration-testing platform that emulates real-world hacker behavior to identify vulnerabilities in applications and infrastructure at scale. The company helps organizations manage security testing, compliance, vulnerability discovery, and remediation, serving more than 1,000 companies across 70+ countries, from fast-growing startups to Fortune 100 enterprises worldwide.








