Job Title: VAPT Engineer – 3+ Years Experience
Job Location: Thrissur | Work from Office | Mon - Sat
Experience: 3 - 5 yrs
Candidate location: Prefers candidates from Kerala
Job Summary
We are looking for an experienced Vulnerability Assessment and Penetration Testing (VAPT) Engineer with 3+ years of experience in application and infrastructure security testing. The candidate will be responsible for identifying security vulnerabilities, performing penetration testing, preparing detailed reports, and supporting remediation activities.
Key Responsibilities:
- Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, mobile applications, and infrastructure.
- Conduct black-box, grey-box, and white-box security testing based on project requirements.
- Identify and validate vulnerabilities such as:
- OWASP Top 10
- SQL Injection
- Cross-Site Scripting (XSS)
- Authentication and authorization issues
- Broken access control
- SSRF
- CSRF
- Security misconfiguration
- API vulnerabilities
- Business logic vulnerabilities
- Perform API security testing, including authentication, authorization, token validation, rate limiting, and API abuse scenarios.
- Conduct network and infrastructure VAPT, including server, network, firewall, and exposed services.
- Perform vulnerability scanning and manual validation using industry-standard tools.
- Analyze scan results and eliminate false positives through manual verification.
- Prepare detailed VAPT reports with vulnerability description, risk rating, evidence, business impact, and remediation recommendations.
- Work with development and infrastructure teams to support vulnerability remediation and retesting.
- Conduct security retesting to verify that identified vulnerabilities have been properly fixed.
- Maintain knowledge of emerging vulnerabilities, CVEs, attack techniques, and security best practices.
- Ensure testing activities comply with organizational security policies and applicable regulatory requirements.
Required Technical Skills
- Minimum 3 years of experience in VAPT / Cybersecurity / Application Security.
- Strong knowledge of OWASP Web and API Security.
- Experience with tools such as:
o Burp Suite
o OWASP ZAP
o Nmap
o Nessus / Qualys
o Metasploit
o SQLMap
o Postman
o HTTP/HTTPS
o REST APIs
o JWT/OAuth/OIDC
o TCP/IP and networking
o Linux and Windows
o Web application architecture
o Databases and SQL
- Ability to perform manual penetration testing, not just automated vulnerability scanning.
- Basic scripting knowledge in Python, PowerShell, Bash, or similar languages is desirable.
- Knowledge of cloud security, preferably Azure/Oracle Cloud/AWS, would be an advantage.
Certifications – Preferred
- CEH
- OSCP
- eJPT
- CompTIA Security+
- CREST certifications
- Other recognized cybersecurity/VAPT certifications
Educational Qualification
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Key Competencies
- Strong analytical and problem-solving skills.
- Good understanding of security risks and their business impact.
- Ability to communicate vulnerabilities clearly to technical and business teams.
- Good documentation and report-writing skills.
- Ability to work independently as well as with development and infrastructure teams.
Work Location: In person