Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Sophos

Penetration Testing Analyst

Sophos

Penetration Testing Analyst conducting application or network penetration tests for Sophos, a global cybersecurity provider. Producing client security reports and leading engagement readiness calls.

Posted 9/8/2026full-timeRemote • 🇮🇳 IndiaMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Information Security with a focus on penetration testing, application security assessments, and vulnerability analysis. Proficient in using various security tools and methodologies to identify and mitigate risks while effectively communicating findings to clients and stakeholders.

Highest-signal resume keywords
Information Security ExperiencePenetration TestingNmapMetasploitCEH Certification

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Penetration TestingApplication Security AssessmentsVulnerability AnalysisNmap ScanningKali LinuxBurp SuiteTCP/IP NetworkingApplication Attack VectorsSecurity Test ProcessesOWASP Top 10
Soft Skills
Client-Facing CommunicationOrganizational SkillsAttention to DetailProblem-Solving SkillsMultitasking Skills
Tools & Technologies
MetasploitKali LinuxBurp SuiteLinuxNetworking Appliances
Certifications & Qualifications
CEHWAPTGPENGWAPTGAWNOSCP
Industry Keywords
Information SecurityApplication SecurityVulnerability AssessmentNetwork Penetration TestingSecurity Assessment Reports

Tech Stack

Tools & technologies
FirewallsLinuxTCP/IP

About the role

Key responsibilities & impact
  • Coordinate activities, documentation, readiness schedules, and information between business, clients, and project teams
  • Act as the point of contact for testing readiness and communicate readiness status
  • Use project management tools to monitor tasks, responsible parties, timelines, and status
  • Report and escalate issues to management
  • Conduct application security assessments for web, mobile, and API applications, or network penetration testing assessments
  • Use off-the-shelf and internally developed exploitation tools for manual testing of advanced attacks
  • Produce and deliver professional security assessment reports detailing vulnerabilities and exploits
  • Lead client conference calls covering test readiness, troubleshooting, project kickoffs, high/critical findings, and close-out reviews
  • Perform proactive research on new threats, vulnerabilities, and exploits
  • Document exploitation findings for client remediation
  • Work independently and as part of a larger team
  • Perform other essential duties as assigned

Requirements

What you’ll need
  • 3+ years of experience in Information Security
  • Excellent client-facing and internal written and verbal communication skills
  • Minimum of 3 years of experience with penetration testing
  • Minimum of 3 years of experience with at least one of: Nmap, Metasploit, Kali Linux, Burp Suite
  • Ability to learn quickly and thrive in a high-energy team environment
  • Professional, “get it done” attitude and strong work ethic
  • Solid organizational skills, attention to detail, and multitasking skills
  • Experience with NMap Scanning (desirable)
  • Understanding of web application authentication methods (desirable)
  • Experience with Linux (desirable)
  • Understanding of networking appliances, including routers, load balancers, firewalls, WAF, IDS/IPS, and web content filter/proxy (desirable)
  • Understanding of tools to validate network access with a penetration testing platform (desirable)
  • Offensive certifications such as CEH, WAPT, GPEN, GWAPT, GAWN, or OSCP (desirable)
  • Knowledge of Microsoft Windows/Linux operating systems administration and internals (desirable)
  • Understanding of TCP/IP networking at a technical level (desirable)
  • Experience with application attack vectors, security test processes, and common vulnerabilities such as OWASP Top 10 (desirable)
  • Good troubleshooting, technical communication, analytical, and problem-solving skills (desirable)
  • Legal authorization to work in India without employer sponsorship

Benefits

Comp & perks
  • Remote-first working model
  • Employee-led diversity and inclusion networks
  • Annual charity and fundraising initiatives
  • Volunteer days
  • Global employee sustainability initiatives
  • Global fitness and trivia competitions
  • Global wellbeing days
  • Monthly wellbeing webinars and training
  • Recruitment and selection process adjustments for accessibility