We are looking for a strong candidate with 2–5 years of hands-on experience in Vulnerability Assessment and Penetration Testing (VAPT) across web applications, APIs, mobile applications, and network infrastructure. Exposure to security testing of AI/LLM-powered applications will be an added advantage.
Job Title: Consultant – Security Testing
Job Summary
We are looking for a skilled VAPT (Vulnerability Assessment and Penetration Testing) Security Consultant to perform security assessments across web applications, mobile applications, APIs, and network infrastructure. The ideal candidate should have hands-on experience in identifying security vulnerabilities, validating risks, preparing detailed technical reports, and communicating findings with clients. The role involves participating in the complete project lifecycle, from pre-sales support and proposal preparation to final report delivery and client presentations.
Key Responsibilities
- Perform Vulnerability Assessment and Penetration Testing (VAPT) for:
- Web Applications
- Mobile Applications (Android/iOS)
- APIs
- Internal and External Network Infrastructure
- Conduct manual and automated security testing to identify, validate, and prioritize vulnerabilities.
- Prepare comprehensive VAPT reports with technical findings, proof of concepts, business impact, risk ratings, and remediation recommendations.
- Communicate assessment findings to clients and provide technical guidance during remediation.
- Manage client interactions throughout the assessment lifecycle.
- Participate in project planning, effort estimation, proposal preparation, and final project delivery.
- Stay updated with the latest security threats, attack techniques, and mitigation strategies.
- Ensure testing methodologies align with industry standards and best practices.
- Support compliance-related security assessments and provide guidance on security requirements.
Required Skills
- Strong understanding of Web Application Security concepts.
- Good knowledge of Mobile Application Security testing.
- Experience in Network Vulnerability Assessment and Penetration Testing.
- Strong understanding of:
- OWASP Top 10
- OWASP API Security Top 10
- OWASP Mobile Top 10
- OWASP LLM Top 10
- SANS/CWE Top Vulnerabilities
- Ability to identify business logic vulnerabilities and perform manual security testing beyond automated tool findings.
- Strong understanding of API Security Testing, including authentication, authorization, JWT, OAuth, and API access controls.
- Excellent report writing and client communication skills.
Preferred Skills
- Knowledge of information security standards and compliance frameworks, including ISO 27001, PCI DSS, SOC 2, HIPAA, GDPR, and similar regulatory requirements.
- Exposure to security assessments of cloud environments (AWS, Azure, or GCP) will be an added advantage.
- Exposure to AI/LLM Security Testing, including Prompt Injection, Sensitive Data Exposure, Excessive Agency, Insecure Output Handling, and other OWASP LLM Top 10 risks.
- Experience testing AI-powered applications, chatbots, copilots, AI agents, RAG-based solutions, or GenAI integrations will be an added advantage.
- Working knowledge of Python and JavaScript for automation, scripting, custom security testing, and proof-of-concept development.
- Familiarity with CI/CD security, DevSecOps practices, and Secure SDLC.
- Exposure to source code review and Static Application Security Testing (SAST) tools is an added advantage.
- Familiarity with AI/LLM security testing methodologies and emerging AI security risks.
Tools & Technologies
Hands-on experience with:
- Burp Suite
- OWASP ZAP
- Nessus
- Nmap
- Postman
- Kali Linux
- Metasploit
- Wireshark
- MobSF
- Snyk
- sqlmap
Preferred Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related field.
- 2–5 years of hands-on experience in VAPT or Application Security.
- Preferred certifications such as CEH, CEH Practical, CompTIA Security+, eJPT, PNPT, or OSCP.
Required Competencies
- Strong analytical and problem-solving skills.
- Excellent written and verbal communication skills.
- Ability to work independently and manage multiple client engagements.
- Attention to detail and commitment to delivering high-quality security assessments.
- Ability to explain technical findings to both technical and non-technical stakeholders.
- Candidates who can independently execute end-to-end security assessments, validate findings manually, and confidently interact with clients will be preferred.
#Hiring
#NowHiring
#SecurityTesting
#CyberSecurity
#CyberSecurityJobs
#VAPT
#PenetrationTesting
#EthicalHacking
#ApplicationSecurity
#AppSec
#WebSecurity
#APISecurity
#MobileSecurity
#NetworkSecurity
#VulnerabilityAssessment
#OffensiveSecurity
#InformationSecurity
#SecurityConsultant
#OWASP
#OWASPTop10
#BurpSuite
#KaliLinux
#RedTeam
#DevSecOps
#CloudSecurity
#AISecurity
#LLMSecurity
#GenAI
#OSCP
#CEH
#eJPT
Pay: ₹800,000.00 - ₹1,500,000.00 per year
Benefits:
- Flexible schedule
- Provident Fund
Work Location: In person