Cyber Security Analyst
Location: Kannur, Kerala (On-site)
Employment Type: Full-time
About HAZERCLOUD
HAZERCLOUD is an AWS Advanced Consulting Partner specializing in cloud architecture, DevOps automation, managed hosting, and cloud security.
We partner with startups and enterprises to design, deploy, and manage secure, scalable, and high-performance AWS environments. With a strong focus on automation, operational excellence, and cybersecurity, we help organizations strengthen their security posture while enabling business growth through modern cloud technologies.
Job Summary
HAZERCLOUD is seeking a highly motivated Cyber Security Analyst to join our growing cybersecurity team. The ideal candidate will be responsible for conducting Vulnerability Assessment and Penetration Testing (VAPT), identifying and validating security vulnerabilities, supporting compliance initiatives, strengthening application security, and collaborating with development and DevOps teams to build secure solutions. This role also involves client interaction, security awareness initiatives, phishing simulations, and mentoring junior security professionals.
Key Responsibilities
Conduct Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, WordPress applications, cloud environments, and supporting infrastructure.
Perform Web Application and API Penetration Testing in accordance with industry best practices, including OWASP Top 10 and OWASP API Security Top 10.
Identify, validate, exploit, and document security vulnerabilities with appropriate risk ratings and business impact analysis.
Prepare comprehensive VAPT reports containing technical findings, proof of concept (PoC), risk assessments, and remediation recommendations.
Perform security re-testing to verify remediation and ensure timely closure of identified vulnerabilities.
Collaborate with developers, DevOps engineers, infrastructure teams, and stakeholders to remediate security issues and improve application security.
Participate in client meetings to define assessment scope, present findings, explain security risks, and recommend mitigation strategies.
Plan and deliver Security Awareness Training sessions to educate employees on cybersecurity best practices.
Design, execute, and evaluate phishing simulation campaigns to improve employee awareness against social engineering attacks.
Support secure software development by providing security guidance throughout the Software Development Life Cycle (SDLC).
Administer and maintain Vanta compliance activities, including evidence collection, policy management, audit preparation, and continuous compliance monitoring.
Support compliance initiatives related to ISO 27001, SOC 2, and other applicable security frameworks.
Monitor remediation activities and ensure timely resolution of identified security risks.
Mentor interns and junior security professionals by providing technical guidance and knowledge sharing.
Contribute to the continuous improvement of security testing methodologies, internal processes, and cybersecurity best practices.
Required Qualifications
Bachelor's degree in Cyber Security, Computer Science, Information Technology, or a related discipline.
Minimum 1–4 years of hands-on experience in Cyber Security, Penetration Testing, or Application Security.
Strong experience performing Web Application, API, and Infrastructure Penetration Testing.
Excellent understanding of OWASP Top 10, OWASP API Security Top 10, CVSS, MITRE ATT&CK, and common attack methodologies.
Hands-on experience with security tools such as Burp Suite Professional, Nmap, Nessus, Metasploit, OWASP ZAP, SQLMap, and similar tools.
Good understanding of authentication mechanisms, session management, networking, HTTP/HTTPS, SSL/TLS, Linux, Windows, and cloud security fundamentals.
Experience preparing professional VAPT reports for clients with clear remediation guidance.
Strong analytical, communication, presentation, and problem-solving skills.
Ability to work independently and collaboratively within cross-functional teams.
Mandatory Certification
Certified Ethical Hacker (CEH)
Preferred Certifications
Offensive Security Certified Professional (OSCP)
CREST Certified Tester (CRT) or other CREST certifications
eLearnSecurity Junior Penetration Tester (eJPT)
AWS Security Specialty or other cloud security certifications are an added advantage.
Preferred Skills
Experience with AWS Cloud Security and Identity & Access Management (IAM).
Knowledge of DevSecOps practices and CI/CD security.
Experience with Vanta compliance management.
Familiarity with scripting using Python, Bash, or PowerShell.
Strong technical documentation and report-writing skills.
Excellent client communication and presentation skills.
Why Join HAZERCLOUD?
Be part of an AWS Advanced Consulting Partner delivering secure cloud and DevSecOps solutions.
Work on real-world security assessments for clients across diverse industries.
Collaborate with experienced cloud architects, DevOps engineers, and cybersecurity professionals.
Gain exposure to cloud security, compliance, DevSecOps, and enterprise security projects.
Access continuous learning, certification opportunities, and career growth in a fast-paced technology environment.
Pay: ₹15,000.00 - ₹45,000.00 per month
Benefits:
- Paid sick time
- Paid time off
- Provident Fund
Work Location: In person