Conduct end-to-end Vulnerability Assessment and Penetration Testing (VAPT) for: o Web Applications o APIs (REST, SOAP, GraphQL) o Mobile Applications (iOS & Android)
- Perform manual and automated security testing using industry tools (BurpSuite Pro, OWASP ZAP, Postman, etc.).
- Identify, validate, and exploit vulnerabilities with proper risk rating and impact assessment.
- Prepare and deliver comprehensive technical reports (detailing findings, exploitation steps, and mitigation recommendations) and executive-level summaries for clients.
- Collaborate with internal teams and clients during remediation to validate fixes.
- Stay up to date with the latest vulnerabilities, exploits, attack techniques, and threat intelligence.
- Adhere to and align assessments with industry frameworks and standards such as OWASP, PTES, NIST, CIS,
PCI DSS.
- Always maintain confidentiality and integrity of client data. • Vulnerability tracker management.
- Leading team onsite for overall project execution.
Required Skills & Competencies
- Web Application Penetration Testing (WAPT)
- API Security Testing (REST, SOAP, GraphQL)
- Mobile Application Security Testing (Android & iOS)
- Vulnerability Assessment and Penetration Testing (VAPT)
- Manual & Automated Security Testing
- OWASP Top 10 & API Security Top 10
- Secure Code Review (preferred)
- Vulnerability Validation & Exploitation
- Risk Assessment & CVSS Scoring
- Threat Modeling (preferred)