Job Title: Cyber Security Tester (4–5 Years Experience)
Job Type: Full-Time / Part-Time
Location: Mohali, Punjab (On-site Preferred)
Experience: 4–5 Years
Job Summary
We are seeking a highly skilled Cyber Security Tester with 4–5 years of hands-on experience in Offensive Security, Vulnerability Assessment & Penetration Testing (VAPT), Web Application Penetration Testing (WAPT), and Network Security Testing. The ideal candidate should have strong expertise in identifying, exploiting, and validating security vulnerabilities across web applications, APIs, networks, and infrastructure while providing detailed remediation recommendations.
Key Responsibilities
- Perform Vulnerability Assessment & Penetration Testing (VAPT) for web applications, APIs, networks, and IT infrastructure.
- Conduct Web Application Penetration Testing (WAPT) in accordance with OWASP Top 10 and the OWASP Testing Guide.
- Perform Network Penetration Testing, including internal and external network assessments.
- Execute Offensive Security engagements to identify and exploit security weaknesses in a controlled environment.
- Assess applications for vulnerabilities such as:
- SQL Injection (SQLi)
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Broken Access Control
- Authentication & Session Management flaws
- Server-Side Request Forgery (SSRF)
- Remote Code Execution (RCE)
- Command Injection
- XML External Entity (XXE)
- Insecure Deserialization
- Security Misconfiguration
- File Upload Vulnerabilities
- Perform API security testing (REST, GraphQL, SOAP).
- Conduct wireless, firewall, and network device security assessments.
- Validate vulnerabilities through manual testing and exploit verification.
- Prepare comprehensive VAPT reports, including risk ratings (CVSS), proof of concept (PoC), and remediation recommendations.
- Re-test vulnerabilities after remediation to verify fixes.
- Stay updated with emerging cyber threats, attack techniques, and security standards.
Required Skills
- 4–5 years of hands-on experience in Cyber Security Testing / Offensive Security.
- Strong expertise in:
- VAPT (Vulnerability Assessment & Penetration Testing)
- WAPT (Web Application Penetration Testing)
- Network Penetration Testing
- Offensive Security Testing
- OWASP Top 10 & OWASP Testing Guide
- Hands-on experience with security tools such as: Burp Suite Professional, Nmap, Nessus / OpenVAS, Metasploit, Wireshark, OWASP ZAP, Nikto, Hydra, SQLMap, Gobuster / Dirsearch
- Strong understanding of TCP/IP, DNS, HTTP/HTTPS, VPNs, Firewalls, Active Directory, Windows, and Linux environments.
- Experience testing REST APIs, JWT, OAuth, SAML, and authentication mechanisms.
- Ability to perform manual penetration testing beyond automated vulnerability scanning.
- Excellent analytical, documentation, and communication skills.
Preferred Qualifications
- Certifications such as OSCP, CEH, eJPT, PNPT, CRTP, CompTIA Security+, or equivalent.
- Experience with cloud security assessments (AWS, Azure, or GCP).
- Knowledge of Mobile Application Penetration Testing (Android/iOS) is an added advantage.
- Familiarity with Secure SDLC and DevSecOps practices.
Why Join Us?
- Work on challenging cybersecurity and offensive security engagements.
- Exposure to diverse web, network, and infrastructure security projects.
- Collaborative work environment with opportunities for technical growth.
- Flexible engagement options – Full-Time or Part-Time.
Pay: ₹20,000.00 - ₹40,000.00 per month
Benefits:
Work Location: In person