Schneider Electric

Engineer II, Cybersecurity Testing and Audit

Schneider Electric Bengaluru, Karnataka, India

Automation Machinery Manufacturing · 10,001+ employees

17 h ago
security Mid (2-5 yrs) Full-time India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The role involves performing penetration testing on various systems to identify security weaknesses and providing clear mitigation recommendations. You will collaborate with project teams and the cybersecurity community to ensure applications align with security policies and standards.

What they look for

Penetration Testing Cybersecurity Web Security Mobile Security API Security Cloud Security Vulnerability Management DevSecOps Python Network Security Operating System Hardening Automation Scripting Risk Assessment Security Audits NIST Cybersecurity Framework

Requirements

Candidates must have at least 4 years of IT security experience, including 3 years specifically in penetration testing across web, mobile, and API platforms. A degree in Computer Science or Information Technology is required, along with relevant certifications such as OSCP, OSCE, or GPEN.

Full description

Cybersecurity Penetration Tester

Schneider Digital is the global IT organization within Schneider Electric. We have, within our Cybersecurity function, an objective to assess the security of our systems, to identify security risks before those materialize. Technical assurance, by means of security testing of the actual system, is crucial so we identify application related issues that need to be addressed.

This role is part of our DE Penetration Testing unit and will focus on performing penetration testing of those systems, and providing clear guidance as to how to address weaknesses identified. The role holder will be working in collaboration with the applications security and compliance regional managers and other IT specialists, to train in Schneider Electric security policies, processes, and tools.

Responsibilities

The Lead Cybersecurity Penetration Tester will work with project teams to ensure applications meet our security policies.

  • Understand project deliverables and application details
  • Run automated and manual security checks (not limited to tools) to uncover security weaknesses in the system
  • Propose mitigation steps for identified risks and threats
  • Provide clear recommendations from a security perspective based on understanding of application, application risk and business context, and results of checks performed.
  • Work alongside the cybersecurity community and application teams.
  • Explore process, reporting and improvement in techniques
  • Ability to collaborate with other penetration teams to align knowledge, tools and techniques

Behaviors and Competencies

  • Strong written and verbal communication skills, with a proven ability to communicate with technical staff, as well as project teams, so security risks are understood in business terms
  • Keep pace with standards and technologies related to security
  • Leadership / Act like owners
  • Collaboration / Teamwork
  • Requirements Gathering and Analysis
  • Interpersonal Skills, proactiveness
  • Willing to learn new skills / Learn Every day and desire to succeed and grow

Skills

  • Security – Web, Mobile, API, Cloud and container security, Thick Client, Network, Operating System
  • Applications Development & Delivery
  • Understanding or experience of any of the following is an advantage:
  • Cloud Security Assessment and Security Audits of Cloud Environment
  • Vulnerability Management (Process, Tools and Metrics)
  • NIST Cybersecurity Framework
  • Critical Security Controls (CSC)
  • Expertise in DevSecOps methodologies is also an advantage.

Knowledge

  • Pentest standards and methodologies, OWASP, SANS etc.
  • Subject matter expert in web/mobile/thick client/API/IoT/IIoT assessments
  • Good understanding of server vulnerabilities (Linux, Windows) and hardening
  • Familiarity with cloud platforms, and cloud container security
  • Efficient and effective usage of pentest tools as well as demonstrate less dependency on tools.
  • Experience with automation, scripting (Python, Perl, Ruby, etc.)
  • Proactive interest in emerging technologies (e.g. Offensive AI) and techniques related to penetration testing
  • Basic understanding of AI/ML concepts and Large Language Models (LLMs) and their integration in modern applications
  • Awareness of security risks in AI/LLM-based systems, including prompt injection, data leakage, and API misuse in GenAI applications
  • Ability to translate technical security topics in a business-friendly manner
  • Demonstrable teamwork skills and resourcefulness
  • Virtual Machines Management

Experience

Essential

  • 4+ years of experience in IT security
  • Min 3+ years of experience in penetration testing of Web, Mobile (iOS & Android), API, Thick client & Network.

Desirable

  • Experience with red teams or CTF (Capture the Flag)
  • Experience with reverse engineering
  • Presented exploit POC/ research concepts at forums like exploit-db.
  • Participated in national/ international cybersecurity conferences.
  • DevSecOps implementation and supporting security tooling is desirable (SAST)

Education and Training

  • BE or MS or MCA Computers Science or Information Technology or related fields
  • Tech Computers Science or Information Technology or related fields
  • Certifications - OSCP, OSCE, GPEN, GXPN, GICSP, GWAPT, OSWP, etc.
  • Azure / AWS security certifications is a plus.
  • CISSP, CEH also a plus

Similar roles