
Real job — pulled straight from Paramount Assure’s careers page · Verified July 15, 2026 · No reposts.
Job description
Paramount Assure is hiring a Security Tester — a full-time, based in Coimbatore, India role. Apply directly on Paramount Assure's careers page below.
Security Tester
Department: AIDA
Experience: 2-5
- Own end-to-end VAPT engagements across web apps, REST/GraphQL APIs, cloud infrastructure, and internal networks — from scoping and threat modelling to exploitation, reporting, and retesting.
- Red-team AI-native applications: prompt injection (direct and indirect), jailbreaks, system-prompt leakage, insecure output handling, RAG poisoning, training-data extraction, model denial-of-service, and excessive-agency abuse in agentic systems.
- Break agents and their tool-chains: test tool/function-calling boundaries, MCP (Model Context Protocol) server exposure, sandbox escapes, and privilege escalation through chained tool calls.
- Map findings to real frameworks — OWASP Top 10, OWASP LLM Top 10, OWASP Agentic Security (ASI), MITRE ATT&CK, and MITRE ATLAS — so remediation is grounded, not hand-wavy.
- Score and prioritize vulnerabilities using CVSS, with clear, reproducible proof-of-concept and business-impact context that both engineers and leadership can act on.
- Write reports people read: crisp, developer-friendly write-ups with reproduction steps, evidence, and pragmatic remediation guidance — not a wall of scanner output.
- Shift security left: help embed automated security testing (SAST, SCA, DAST, secret scanning, IaC scanning, LLM red-team checks) into CI/CD pipelines and PR gates.
- Retest and verify fixes, track remediation to closure, and partner with engineering to make the fix stick.
- Stay ahead of the curve — track emerging AI attack techniques and feed new test cases back into our internal red-team playbooks.
- 2.5+ years of hands-on offensive security / penetration testing experience.
- Demonstrated experience with the full VAPT lifecycle for web, API, and cloud targets — you can scope, exploit, and communicate, not just run a tool.
- Strong grasp of the OWASP Top 10 and common web/API vulnerability classes (authn/authz flaws, injection, SSRF, IDOR, deserialization, misconfigurations).
- Working knowledge of LLM and AI application attack surfaces — prompt injection, jailbreaks, insecure output handling, and the OWASP LLM Top 10 — or a clear, provable appetite to go deep here fast.
- Hands-on with core offensive tooling: Burp Suite, OWASP ZAP, Nmap, Nuclei, Metasploit, sqlmap, and similar.
- Comfortable in at least one scripting language (Python strongly preferred) to build custom exploits, harnesses, and automation.
- Solid understanding of web protocols, authentication/authorization (OAuth 2.0 / OIDC, JWT, session management) and how they break.
- Familiarity with cloud security fundamentals (AWS, Azure, or GCP) and containerized environments (Docker, Kubernetes).
- Ability to write clear, prioritized, reproducible reports and explain risk to both engineers and non-technical stakeholders.
- Hands-on experience with LLM/agent red-teaming frameworks: Garak, PyRIT, DeepTeam, promptfoo, or Microsoft’s AI Red Teaming Agent.
- Experience with AI guardrail / defense tooling: Lakera Guard, Rebuff, Llama Prompt Guard, or custom prompt-injection classifiers.
- Familiarity with MCP security and agent-sandboxing concepts (MCP Scan, tool-permission boundaries, isolation).
- Exposure to RAG pipeline security, vector-store poisoning, and multi-agent orchestration risks.
- Knowledge of MITRE ATLAS and the NIST AI Risk Management Framework (AI RMF).
- Experience integrating security testing into CI/CD (GitHub Actions, GitLab CI) and policy-as-code gating (OPA / Rego).
- Cloud-native security experience with Kubernetes (RBAC, network policies, admission control).
- Bug-bounty track record, CTF wins, published research, or CVEs to your name.
Get Security Tester jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs
Frequently asked questions
What skills are required for Security Tester at Paramount Assure?
The required skills for Security Tester at Paramount Assure include: Python, OAuth, AWS, Azure, GCP, Docker, Kubernetes, GitHub Actions, GitLab CI.
What is the seniority level for Security Tester at Paramount Assure?
Security Tester at Paramount Assure is a Mid Level / Senior level position.
How do I apply for Security Tester at Paramount Assure?
You can view the full description and apply for Security Tester at Paramount Assure on EchoJobs: https://echojobs.io/job/paramount-assure-security-tester-hsvcm.


