Job Title: VAPT Security Analyst – L1/L2
Experience: 1–5 Years
Location: Kochi
Department: Cyber Security
Role Summary
We are looking for a motivated VAPT Security Analyst (L1/L2) to perform vulnerability assessments, basic penetration testing, and security validation activities across web applications, APIs, networks, cloud, and infrastructure. The ideal candidate should possess a strong foundation in offensive security concepts and demonstrate hands-on knowledge of industry-standard security tools.
Key Responsibilities
- Perform vulnerability assessments on web applications, APIs, internal/external networks, operating systems, and cloud environments.
- Conduct basic penetration testing under the guidance of senior security consultants.
- Identify, validate, and classify vulnerabilities using CVSS standards.
- Prepare detailed technical assessment reports with remediation recommendations.
- Execute security scans using industry-standard vulnerability assessment tools.
- Verify remediation through re-testing and validation.
- Stay updated with the latest vulnerabilities, attack techniques, and security advisories.
- Maintain proper documentation and assessment evidence.
- Assist senior consultants during Red Team and security assessment engagements.
Required Technical Skills
- Good understanding of OWASP Top 10, MITRE ATT&CK, and CVSS.
- Knowledge of TCP/IP, DNS, HTTP/HTTPS, VPN, Firewalls, Active Directory, and Windows/Linux administration.
- Hands-on experience with:
- Burp Suite
- Nessus
- Nmap
- Nikto
- Metasploit (basic)
- Wireshark
- Kali Linux
- Basic scripting knowledge (Python, Bash, or PowerShell) is an advantage.
- Familiarity with API security testing and authentication mechanisms.
Required Certifications
- CEH (EC-Council) – Baseline expectation for all VAPT staff.
- OSCP (Offensive Security) – Strongly preferred as the practical benchmark.
- GIAC GPEN or GIAC GWAPT – Preferred.
- CREST CRT/CCT – Preferred.
Good to Have
- Knowledge of cloud security (AWS, Azure, GCP).
- Basic understanding of container security (Docker/Kubernetes).
- Exposure to SIEM and Endpoint Security solutions.
Work Location: In person