Loading page...
Loading page...
Join freshers getting daily off-campus drives, internships & Remote jobs
Loading job details...
Crypto Mize
Experience / Eligibility
CS / IT / Engineering Graduate
Salary
Not Disclosed / As per Industry Standards
Location
Mumbai, Maharashtra, India
Penetration Tester jobs in Delhi at CryptoMize are open on a rolling, always-hiring basis — client demand for web, Android, and network pentesting runs continuously across our security practice, and we staff ahead of it. This is a full-time, permanent position with immediate joining, based at our New Delhi HQ, executing authorized offensive-security engagements for clients who need to know what a determined adversary would actually reach. Below is the complete posting: the responsibilities, the requirements, the seniority ladder, and the selection process. Testers whose findings developers thank them for should read to the end.
LOCATION New Delhi (HQ)
EMPLOYMENT Full-time · Permanent
AVAILABILITY Immediate · Rolling intake
COMPENSATION Discussed at screening
TRACKS ON THIS DESK25
CRAFT SKILLS NAMED12
TOOLS & SYSTEMS6
PATH STAGES4
01
01The actual work
What will you actually do as a Penetration Tester at CryptoMize?
01
Run commissioned test engagements from kickoff to close: scope confirmation, test windows, communication protocol, and the daily check-ins clients on live systems require
02
Attack web applications the way a real intruder would: map the attack surface, chain the weak points, and demonstrate impact with controlled proof — never destruction
03
Test mobile builds on real devices: storage exposure, interception points, weak certificate pinning, and the trust decisions an app makes about its own server
04
Probe internal networks from a foothold: privilege paths, trust relationships, and the route from one compromised workstation to the crown jewels
05
Write the report the client's engineers will actually work from: reproduction steps, evidence captures, severity with rationale, and fixes that name the file to change
06
Return for verified retests: confirm each fix holds, close what holds, and escalate what was patched in name only
07
Test the human protocol too — authorized phishing simulations and physical-entry checks where the engagement's rules permit
ROLE RESPONSIBILITIES
As a Penetration Tester at CryptoMize you will identify the target systems and the goal for each engagement, review the available information, and undertake the variety of methods available to assess whether a determined adversary could breach the client’s web applications, mobile stacks, or networks — always inside a written authorization, always inside its scope. The penetration-test process is deliberate: reconnaissance before contact, verified exploitation over scanner noise, and evidence that reconstructs the attack path for the client’s engineers.
Testers here are also known as ethical hackers, and the ethics are load-bearing. You will spend your working days attempting to breach computer systems and networks — with explicit permission, within explicit boundaries, and with the client’s defense as the only beneficiary. Every finding carries dual accountability: technical accuracy in what you demonstrated, and professional judgment in how the demonstration is evidenced, stored, and eventually destroyed.
The role carries a standing teaching duty: supervising pentest interns through their first client engagements, reviewing their findings drafts, and feeding conversion decisions. Remote testing of client networks alternates with on-site assessments as engagements require — and the documentation discipline travels with you either way, because at CryptoMize the report is the product; the exploit is just how it was earned.
02
02Capability profile
What skills and tools does a Penetration Tester need?
astro-island,astro-slot,astro-static-slot{display:contents}
Craft skills12 Tools & systems6 Offer standards4
Engagement management on live client systems — communication protocol, windows, rollback triggersAttack-surface mapping before touching anythingChained exploitation demonstrated with controlled proofMobile assessment on real devicesInternal privilege-path probing from a foothold Engineer-readable reporting — reproduction, evidence, named fixesVerified-retest disciplineAuthorized phishing and physical-entry simulation where scope permitsTool judgment — proxy suites, exploit frameworks, custom scripts each in their right placeScope obedience (absolute — the authorization is the job)Clearance eligibility and client-trust verificationTeaching testers the craft through engagement review
Burp Suite Professional (web application testing)Nmap (reconnaissance and enumeration)Metasploit Framework (exploitation)Kali Linux toolchainWireshark (traffic analysis)Custom Python/Bash tooling for engagement-specific needs
Depth of demonstrated skill in the specific role disciplineClassification and scope of the client engagement the role supportsUrgency and time-sensitivity of active project requirementsTrack record built across CryptoMize engagements
Also known as: pen testing jobs · pentester vacancy · ethical hacker · security tester
03
03Seniority ladder
Penetration Tester — seniority path at CryptoMize
Tester progression follows engagement quality — the findings you produced, the clients who requested you back, and the juniors you leveled up. The ladder below is how the security practice is actually organized.
Penetration Tester
Owns full-cycle assessments on assigned engagements, with report sign-off and client-facing findings duties.
1/4
Senior Penetration Tester
Leads multi-platform engagements, defines rules of engagement, reviews all findings, and mentors testers and interns.
2/4
Red Team Lead
Runs the offensive-security capability — adversary simulation programs, methodology standards, and engagement staffing across the practice.
3/4
Security Practice Principal
The crossover track: testers who graduate into principal-level client counsel across the five domains, defending infrastructure at strategy altitude.
4/4
04
04The engagement surface
CryptoMize work a Penetration Tester touches
Every role plugs into live engagements across the five Penta-P domains — these are the services your work feeds.
Penetration Tester · Job Opening
This seat plugs into 6 live CryptoMize services across the five Penta-P domains — the work below is where yours lands.
6 SERVICESPENTA-P
Penetration Testing
Vulnerability Assessment
Website Security
Network Security
Cyber Threat Intelligence
Security Training
WHAT DOES PENETRATION TESTER COMPENSATION DEPEND ON?
Compensation is discussed during screening — never a fixed public figure, because it varies per person and per engagement. It depends on:
OFFER CONSTRUCTION FACTOR
01 Depth of demonstrated skill in the specific role discipline
02 Classification and scope of the client engagement the role supports
03 Urgency and time-sensitivity of active project requirements
04 Track record built across CryptoMize engagements