
Senior Embedded Systems Penetration Tester
- Bangalore, Karnataka
- Permanent
- Full-time
- Conduct penetration testing of host/cloud-based applications, perform network security assessments, software/firmware analysis scans, evaluate and prioritize vulnerabilities using CVSS scoring, and document findings using organization-specific reporting tools
- Research network-related protocols for network-connected products, including Industrial Control Systems (ICS), and perform related security assessments
- Responsible for supporting nVent’s product cybersecurity verification testing program which is aligned to the ISA/IEC 62443 4-1 Security Development Lifecycle (SDL)
- Participate in continual efforts to automate as much testing as possible
- Creating test report documentation to provide evidence of compliance to requirement
- Support development and maintenance of a calendar of recurring cybersecurity audits, assessments, and activities; track to ensure owners complete activities on time
- Maintaining list of tested products in appropriate nVent tools/databases
- Work with product development teams to fill gaps found during verification testing
- Bachelor’s degree or equivalent experience in related field
- Ideally 5 years of experience in Penetration Testing, Application Security, QA, Network/IoT, or Offer Testing roles.
- Familiarity with test automation scripting tools or language
- Familiarity with daily activity planning tools such as Atlassian Jira
- Familiarity with either Agile or Kanban work environment
- Ability to collaborate across key functions including IT and product engineering teams
- Familiar with industry standards and best practices
- Good verbal and written communication skills
- Proven experience in Embedded Product Cybersecurity testing
- Familiarity with ISA/IEC 62443 4-1 Security Development Lifecycle (SDL) requirements
- Familiarity with Cybersecurity testing tools such as Burp suite/ZAP, BDBA, SAST, DAST, Fuzzing, and VA tools such as Nessus or Rapid7
- Familiarity with Microsoft Threat Modelling tool
- Demonstrated participation in Capture the Flag (CTF) cybersecurity contests with proven rankings or achievements