Job Description
Position - Penetration Tester
Experience – 2-3 year
Company - ZyBiSys Consulting Services LLP
Location - Bangalore
As Penetration Tester Engineer, you will be responsible for simulating real-world cyberattacks to
identify vulnerabilities, assess risks, and improve security defenses. You will
work closely with security analysts, DevOps, and IT teams to enhance the
organization's resilience against cyber threats.
· Perform Web, API, Cloud, and Network penetration testing across FinTech infrastructures.
· Conduct Red Team & adversary simulations (phishing, lateral movement, privilege escalation, persistence).
· Execute cloud security assessments with focus on PCI DSS, SOC 2, ISO 27001.
· Research, develop, and use custom exploits, scripts, and payloads.
· Identify vulnerabilities, prepare exploit PoCs, and advise on remediation.
· Deliver executive-level security reports and detailed technical findings.
· Stay ahead of new exploits, malware tactics, and FinTech-specific attack surfaces.
· Web & API: Burp Suite Pro, OWASP ZAP, Postman, sqlmap
· Network: Nmap, Nessus, OpenVAS, Hydra, CrackMapExec
· Exploitation: Metasploit, Cobalt Strike, Empire, Covenant
· AD/Windows: BloodHound, Mimikatz, Rubeus, PowerView, SharpHound
· Forensics/Monitoring: Wireshark, tcpdump, Zeek, Suricata
· Python, Bash, PowerShell (for exploit scripting & automation).
· OSCP, OSWE, OSEP, CRTO, GPEN, CEH (Practical), eJPTv2.
About Zybisys:
At ZyBiSys, our success is driven by
innovation and technical excellence. We deliver top-tier IT solutions and
services, ensuring seamless connectivity and efficient infrastructure
management for our clients. Additionally, we specialize in managing cybersecurity,
information security, and compliance to safeguard our customers' digital
environments.
Skills Required
- 2-3 years of penetration testing experience
- Experience performing web, API, cloud, and network penetration testing
- Experience conducting red-team and adversary simulations, including phishing, lateral movement, privilege escalation, and persistence
- Knowledge of PCI DSS, SOC 2, and ISO 27001
- Ability to research and develop custom exploits, scripts, and payloads
- Experience identifying vulnerabilities and preparing exploit proof-of-concepts
- Proficiency with web and API security tools including Burp Suite Pro, OWASP ZAP, Postman, and sqlmap
- Proficiency with network security tools including Nmap, Nessus, OpenVAS, Hydra, and CrackMapExec
- Proficiency with exploitation tools including Metasploit, Cobalt Strike, Empire, and Covenant
- Proficiency with Active Directory and Windows security tools including BloodHound, Mimikatz, Rubeus, PowerView, and SharpHound
- Proficiency with forensics and monitoring tools including Wireshark, tcpdump, Zeek, and Suricata
- Python, Bash, and PowerShell scripting skills
- OSCP certification
- OSWE certification
- OSEP certification
- CRTO certification
- GPEN certification
- CEH Practical certification
- eJPTv2 certification
What We Do
ZYBISYS CONSULTING SERVICES LLP is an India-based IT services and consulting firm focused on helping fintech and other businesses modernize technology. It provides public, private, and hybrid cloud hosting, managed IT services, DevOps, data-center management, infrastructure support, cybersecurity, and technology consulting. Its offerings also include software development, automation, monitoring, and cloud-native solutions designed to improve scalability, operational efficiency, security, and business continuity.








