About Flyrotech Technologies
Flyrotech Technologies is looking for a skilled and passionate VAPT / Security Auditor with 3–6 years of experience in application security testing. The ideal candidate should have strong expertise in API Security Testing, complemented by hands-on experience in Web Application VAPT and Mobile Application VAPT. The role involves identifying security vulnerabilities, performing penetration testing, validating remediation, and ensuring applications meet industry security standards.
Key Responsibilities
- Perform comprehensive API Security Testing for REST, SOAP, GraphQL, and gRPC services.
- Assess APIs against the OWASP API Security Top 10, including BOLA, Broken Authentication, Broken Authorization, Rate Limiting, and other API security vulnerabilities.
- Validate OAuth 2.0, JWT implementation, and API authentication and authorization mechanisms.
- Conduct Swagger/OpenAPI contract testing.
- Perform Web Application Vulnerability Assessment and Penetration Testing (VAPT) covering OWASP Top 10 vulnerabilities, business logic flaws, Cross-Site Scripting (XSS), SQL Injection, CSRF, and security code reviews.
- Conduct Mobile Application Security Testing for Android and iOS applications based on OWASP MASVS.
- Perform SSL pinning bypass, dynamic instrumentation using Frida and Objection, and root/jailbreak analysis.
- Identify, document,
and report security vulnerabilities with remediation recommendations.
- Validate security fixes through re-testing.
- Prepare detailed VAPT reports and collaborate with development and security teams to address findings.
Required Skills
- 3–6 years of hands-on experience in API Security Testing, Web Application VAPT, and Mobile Application VAPT.
- Strong understanding of OWASP API Security Top 10 and OWASP Top 10.
- Experience testing REST, SOAP, GraphQL, and gRPC APIs.
- Knowledge of OAuth 2.0, JWT, API authentication, and authorization mechanisms.
- Experience with OWASP MASVS for mobile application security testing.
- Hands-on experience with Burp Suite Skilled, Postman, SoapUI, OWASP ZAP, MobSF, Frida, Objection, Metasploit, and Python scripting.
- Strong analytical, troubleshooting, communication, and report-writing skills.
Preferred Certifications
- CEH (Certified Ethical Hacker)
- OSCP (Offensive Security Certified Professional)
- CASP+
- eWPT (eLearnSecurity Web Application Penetration Tester)
- eMAPT (eLearnSecurity Mobile Application Penetration Tester)
Interested candidates are requested to share their updated resume to
[email protected] with the subject line: "Application for VAPT / Security Auditor".
Pay: ₹800,000.00 - ₹1,000,000.00 per year
Work Location: Remote
📌 VAPT / SECURITY AUDITOR (India)
🏢 Flyrotech Technologies
📍 India