Penetration Testing Staff Engineer - 5+ yrs

Posted 12 Days Ago
Easy Apply
Be an Early Applicant
Bengaluru, Bengaluru Urban, Karnataka
In-Office
Senior level
Security • Cybersecurity
The Role
As a Staff Penetration Tester, you will perform vulnerability assessments and penetration testing across SonicWall products, collaborating with multiple teams to enhance security.
Summary Generated by Built In

SonicWall is a cybersecurity forerunner with more than 30 years of expertise and is recognized as a leading partner-first company, ensuring our partners and their customers are never alone in the fight against cybercrime. With the ability to build, scale and manage security across the cloud, hybrid and traditional environments in real-time, SonicWall provides relentless security against the most evasive cyberattacks across endless exposure points for increasingly remote, mobile and cloud-enabled users. With its own threat research center, SonicWall can quickly and economically provide purpose-built security solutions to enable any organization—enterprise, government agencies and SMBs—around the world. For more information, visit www.sonicwall.com or follow us on TwitterLinkedInFacebook and Instagram.

Department: Product Security / PSIRT

Overview

As a Staff Penetration Tester within the SonicWall PSIRT, you will assess the security of SonicWall’s web applications, firmware, and network security products. This hands-on technical role involves performing end-to-end vulnerability assessments, penetration testing and coordinated vulnerability research across SonicWall’s full product ecosystem.

Key Responsibilities:

Penetration Testing & Vulnerability Assessment

  • Perform manual and automated penetration testing across web applications, firmware, and network appliances.
  • Identify, exploit, and document vulnerabilities across diverse layers — from web interfaces to embedded firmware and network protocols.
  • Conduct vulnerability scanning of SonicWall products, VMs, servers, and backend systems
  • Execute firmware and binary analysis using tools such as IDA Pro, Ghidra, and binwalk to uncover low-level security flaws.
  • Perform web and API pen testing targeting OWASP Top 10 and emerging web vulnerabilities (e.g., SSRF, deserialization, logic flaws).
  • Assess firmware update mechanisms, cryptographic implementations, and secure boot processes for tampering or privilege escalation risks.
  • Prepare detailed vulnerability reports including exploit paths, root cause analysis, and recommended remediations.
  • You will collaborate closely with engineering, QA, and development teams to identify, validate, and mitigate vulnerabilities — ensuring SonicWall products meet the highest standards of security and resilience.
  • Support PSIRT investigations, including triage of internally discovered and externally reported vulnerabilities.
  • Contribute to tooling, automation, and scripts that enhance penetration testing efficiency and coverage.
  • Conduct independent research on novel web, network, and firmware vulnerabilities.
  • Develop internal methodologies and knowledge base for consistent test execution across product domains.

Required Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Computer or Electrical Engineering, or equivalent experience.
  • 5+ years of experience in penetration testing, red teaming, or vulnerability research.
  • Strong understanding of network protocols, web application security, and firmware architectures.
  • Proficiency with tools such as Burp Suite, Nmap, Nessus, Metasploit, IDA Pro, Ghidra, binwalk, Scapy, Wireshark, and OWASP ZAP.
  • Working knowledge of web technologies (HTTP/S, REST, TCP/IP, DNS, SMTP), Linux internals, and scripting languages (Python, Bash, PowerShell).
  • Ability to perform source code reviews in C/C++, Java, C#, or Python for security flaws.
  • Strong communication skills — capable of presenting technical findings to both engineers and management.
  • High attention to detail, strong analytical thinking, and self-driven approach to testing complex environments.

Preferred Qualifications

  • Certifications: CEH, OSCP, GPEN, GWAPT, OSWE, GREM, or equivalent.
  • Experience with secure development lifecycle (SDLC) integration and DevSecOps automation.
  • Familiarity with exploit development, fuzzing frameworks (boofuzz, Peach), or custom test harnesses.
  • Understanding of cryptographic mechanisms, secure boot, and firmware validation.
  • Prior experience contributing to CVE reporting or vulnerability disclosure programs (VDP/bug bounty).

#LI-NR5

#LI-Hybrid 


SonicWall is an equal opportunity employer.  

We are committed to creating a diverse environment and are an equal opportunity employer. All qualified applicants receive consideration for employment without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.
At SonicWall, we pride ourselves on recruiting a diverse mix of talented people and providing active security solutions in 100+ countries.

Applicant Privacy Notice

Top Skills

Bash
Burp Suite
Ghidra
Ida Pro
Metasploit
Nessus
Nmap
Owasp
Penetration Testing
Powershell
Python
Scapy
Vulnerability Assessment
Wireshark
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Milpitas, CA
1,832 Employees
Year Founded: 1991

What We Do

SonicWall has been fighting the cyber-criminal industry for over 25 years defending small, medium-size businesses and enterprises worldwide. Backed by research from the Global Response Intelligent Defense (GRID) Threat Network, our award-winning real-time breach detection and prevention solutions, coupled with the formidable resources of over 10,000 loyal channel partners around the globe, are the backbone securing more than a million business and mobile networks and their emails, applications and data. This combination of products and partners has enabled a real-time cyber defense solution tuned to the specific needs of the more than 500,000 global businesses in more than 215 countries and territories.

Similar Jobs

CrowdStrike Logo CrowdStrike

Senior Software Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
16 Locations
10000 Employees

CrowdStrike Logo CrowdStrike

Senior Systems Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Hybrid
Bangalore, Bengaluru Urban, Karnataka, IND
10000 Employees

ZS Logo ZS

Senior Engineer

Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Hybrid
2 Locations
13000 Employees

ZS Logo ZS

Data Science Manager - Supply Chain & Manufacturing

Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Hybrid
3 Locations
13000 Employees

Similar Companies Hiring

Silverfort Thumbnail
Security • Sales • Information Technology • Cybersecurity • Automation
GB
507 Employees
Oso Thumbnail
Software • Security • Infrastructure as a Service (IaaS)
New York, New York
36 Employees
Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account