Want to know if this job is worth applying to?
Bengaluru, Karnataka, India
Onsite
Job Description:
Job Title: Senior Penetration Tester(Sr. Penetration Tester)
Department: Security Assurance
Reports To: Senior Manager, Security Assurance Section
Location: Bangalore or Indore, India
About the Team/Department:
At Rakuten Mobile Security Assurance, you will help secure one of the world's most advanced cloud-native telecom networks, protecting millions of customers across digital, mobile, cloud, and AI-driven services.
You will work on cutting-edge offensive security challenges spanning 4G/5G telecom platforms, cloud-native infrastructure, applications, APIs, AI/ML systems, and emerging technologies.
We offer an environment where innovation is encouraged, continuous learning is supported, and security experts are empowered to make a direct business impact.
You will have the opportunity to work alongside industry-leading engineers, build next-generation security capabilities, leverage AI to transform security testing, and contribute to protecting critical telecommunications infrastructure at scale.
If you are passionate about offensive security, enjoy solving complex technical challenges, and want to shape the future of cybersecurity in the AI era, we would love to hear from you.
Position Summary
Perform advanced penetration testing and offensive security assessments across Rakuten Mobile's web, mobile,
API, cloud, AI/ML, and telecom environments. The role focuses on identifying complex security vulnerabilities,
validating exploitability, supporting red team activities, and helping engineering teams strengthen the
organization's security posture.
Key Responsibilities
• Conduct manual and automated penetration testing of web applications, mobile applications, APIs, cloud
platforms, and network infrastructure.
• Perform security assessments of AI/ML applications, LLM-based systems, AI agents, RAG implementations,
and MLOps pipelines.
• Identify vulnerabilities such as prompt injection, insecure model integrations, data leakage, model
manipulation, and AI supply chain risks.
• Execute security testing of telecom systems, including BSS/OSS applications, eSIM platforms, subscriber
management systems, mobile network services, and internet-facing telecom applications.
• Support red team exercises, adversary emulation engagements, attack path analysis, and exploit validation.
• Conduct source code reviews, secure design reviews, and architecture-level security assessments when
required.
• Develop proof-of-concepts, create detailed technical reports, and provide actionable remediation
recommendations.
• Validate remediation fixes and perform security re-testing to confirm closure.
• Research emerging attack techniques, exploit methodologies, AI-assisted testing methods, and offensive
security tools.
• Contribute to automation initiatives and continuous security validation capabilities.
Required Qualifications
• 10+ years of hands-on penetration testing and application security experience.
• Strong expertise in web, mobile, API, cloud, infrastructure, and AI security testing.
• Experience with Burp Suite, Kali Linux, Metasploit, BloodHound, Nmap, Nessus, and modern offensive security
frameworks.
• Knowledge of programming and scripting languages such as Python, JavaScript, Bash, and PowerShell.
• Familiarity with cloud platforms such as AWS, Azure, or GCP and containerized environments such as
Kubernetes and Docker.
Preferred Qualifications
• Experience with telecom technologies, mobile core networks, BSS/OSS systems, and cloud-native telecom applications is preferred.
• Preferred certifications: OSCP, CRTP, CRTO, OSEP, OSWE, GPEN, GXPN or equivalent certifications.
Nice-to-Have Expertise
• AI/LLM security testing and adversarial machine learning.
• Red team operations and advanced exploit development.
• Cloud and Kubernetes security assessments.
• 5G / telecom security testing and BSS/OSS security validation.
• Bug bounty, vulnerability research, and AI-assisted penetration testing.
Core Competencies