| Detail | For this role |
|---|---|
| Department | Information Technology |
| Level | Mid level |
| Reports to | IT Security Manager |
| Direct reports | None |
| Experience | 2 to 6 years in penetration testing, VAPT or application security |
Penetration Tester job description template
Copy this job description, replace the text in square brackets and post it on your careers page or a job portal.
Job title: Penetration Tester
Department: Information Technology
Reports to: IT Security Manager
Location: [City], [office, branch or site]
About the role
A Penetration Tester finds security weaknesses by attacking systems the way a real attacker would, with written permission and an agreed scope. They test web and mobile applications, APIs, networks and cloud setups, and sometimes staff through phishing exercises, then write reports that show impact and how to fix each issue. In India the role sits in cybersecurity consultancies, IT services firms, banks and product companies, under a security manager or VAPT lead. A good Penetration Tester finds what scanners miss and explains risk clearly to developers.
Key responsibilities
- Agree scope, rules of engagement, test windows and written authorization with the client or system owner before testing.
- Test web applications and APIs for OWASP Top 10 issues such as injection, broken access control and weak authentication.
- Test Android and iOS apps for insecure storage, weak certificate pinning and exposed secrets.
- Run internal and external network tests to find exposed services, weak configurations and privilege escalation paths.
- Review AWS or Azure configurations for public storage, over-permissive IAM and exposed management ports.
- Chain low-risk findings into realistic attack paths that show business impact.
- Capture evidence with screenshots and request logs, and stop at once if testing threatens production stability.
- Write reports with risk ratings, proof of concept, impact and clear remediation steps for developers.
- Retest fixed issues and confirm closure in a follow-up report.
- Keep skills current through labs, CTFs and vulnerability research, and build internal test scripts.
Requirements
- B.E., B.Tech, B.Sc or MCA in computer science or IT
- OSCP, CEH Practical, eJPT or eWPT certification
- OSWE or CRTP is an advantage
- 2 to 6 years in penetration testing, VAPT or application security
KRAs and KPIs for a Penetration Tester
Key result areas for the appraisal form, each with a KPI you can measure every month or quarter.
| Key result area | How to measure it |
|---|---|
| Test delivery | Assigned tests completed within the agreed window, with no out-of-scope testing |
| Finding quality | Every high or critical finding backed by a reproducible proof of concept |
| Report timeliness | Final report delivered within 5 working days of test completion |
| Retest turnaround | Retests completed within 3 working days of a fix being ready |
| Test coverage | OWASP testing checklist fully covered in every web and API assessment |
| Report clarity | Feedback of 4 or more out of 5 from clients or developers on report clarity |
Skills and tools
Tools used day to day: Burp Suite Professional, Nmap, Metasploit, Kali Linux, OWASP ZAP, MobSF and Frida, sqlmap.
Reporting line and career path
Next roles: Security Architect, IT Security Manager
Interview questions for a Penetration Tester
- Walk me through how you would test an e-commerce checkout for business logic flaws.
- How do you test for broken access control in an API that uses JWT tokens?
- You find a critical SQL injection on the first day of a test. What do you do?
- How would you get past certificate pinning in an Android app during a test?
- What must a finding contain so a developer can fix it without calling you?
- Tell me about a vulnerability you found that scanners missed.
Managing a Penetration Tester in ZeniaHR
Hire and manage your information technology team in one place
Post the role, onboard the new hire, and track attendance, leave and KRAs in ZeniaHR. Free for your first 50 employees.
Book a free demoSee pricingFrequently asked questions
What does a penetration tester do?
A penetration tester attacks applications, networks and cloud systems with permission and an agreed scope, to find security weaknesses before criminals do. They test web apps, APIs, mobile apps and infrastructure, prove impact with safe proofs of concept, write reports with fixes and retest after developers close the issues.
What is the difference between VAPT and penetration testing?
VAPT stands for vulnerability assessment and penetration testing, a term widely used by Indian companies and regulators. The assessment part uses scanners to list known weaknesses. The penetration testing part goes further, with manual attempts to exploit and chain weaknesses to show real impact. Most VAPT engagements include both.
Which certification is best for a penetration tester in India?
OSCP from OffSec is the most respected hands-on certification and is often requested for senior roles. CEH Practical, eJPT and eWPT are common starting points, and OSWE or the Burp Suite Certified Practitioner stand out for web-focused roles. Employers also look at CTF results, bug bounty reports and published write-ups.