We are looking for a skilled VAPT professional to conduct vulnerability assessments and penetration tests across web applications, mobile applications, networks, APIs, and cloud infrastructure for client engagements. The role involves identifying security weaknesses, exploiting vulnerabilities in a controlled manner, and delivering clear, actionable reports to clients.
Key Responsibilities
- Conduct black box, grey box, and white box penetration tests on web applications, mobile apps (Android/iOS), APIs, network infrastructure, Active Directory Pentesting, and cloud environments (AWS, Azure, GCP).
- Perform vulnerability assessments using automated tools and manual testing techniques aligned with OWASP Testing Guide, OWASP ASVS, PTES, and NIST methodologies.
- Identify, validate, and document security vulnerabilities, providing proof of concept where applicable.
- Perform configuration reviews, source code reviews, and secure code analysis where required.
- Draft detailed technical reports including risk ratings (CVSS scoring), business impact, and remediation recommendations.
- Support retesting cycles to confirm vulnerability closure.
- Coordinate with client technical teams and internal stakeholders during engagement scoping, execution, and reporting phases.
- Stay current with emerging vulnerabilities, attack techniques, CVEs, and threat intelligence.
- Ensure all testing activities comply with defined scope, rules of engagement, and legal/contractual boundaries.
- Maintain confidentiality and data security standards for all client information and findings.
Required Skills and Qualifications
- Bachelor's degree in Computer Science, Information Technology, or related field (or equivalent practical experience).
- 1 to 5 years of hands on experience in VAPT, red teaming, or offensive security (adjust range based on seniority).
- Strong understanding of common vulnerability classes (OWASP Top 10, SANS Top 25, injection flaws, authentication and session management issues, business logic flaws).
- Proficiency with tools such as Burp Suite, Nmap, Metasploit, Nessus, Nikto, SQLmap, OWASP ZAP, and similar.
- Working knowledge of scripting languages (Python, Bash, PowerShell) for automation and custom exploit development.
- Familiarity with network protocols, operating systems (Windows, Linux), and cloud security fundamentals.
- Good report writing and client communication skills.
Preferred Certifications
- OSCP, CEH, CPENT, GPEN, eJPT, or equivalent recognized certifications (preferred, not always mandatory).
Pay: ₹350,000.00 - ₹1,000,000.00 per year
Ability to commute/relocate:
- Hyderabad, Telangana (Hyderabad, Hyderabad District): Reliably commute or planning to relocate before starting work (Preferred)
Experience:
- Penetration testing: 1 year (Preferred)
Work Location: In person