03 Aug
|
Cywarden
|
India
VAPT (Vulnerability Assessment & Penetration Testing) Intern
Location: Mohali, Punjab (On-site)
Job Type: Internship
Shift: US Shift (Monday–Friday)
About the Role
We are looking for a passionate VAPT Intern who has a strong foundation in cybersecurity, secure coding practices, web application security, and ethical hacking. The ideal candidate should have hands-on experience through internships, personal projects, Capture The Flag (CTF) competitions, or bug bounty programs. Candidates with relevant cybersecurity certifications will be preferred.
Key ResponsibilitiesVulnerability Assessment & Penetration Testing
- Perform vulnerability assessments and penetration testing on web applications, APIs, networks, and systems.
- Identify, validate, and document security vulnerabilities.
- Conduct reconnaissance, enumeration, exploitation (where authorized), and post-assessment reporting.
- Assist in verifying remediation efforts through re-testing.
Web & API Security Testing
- Perform security testing against the OWASP Top 10 and OWASP API Security Top 10 vulnerabilities.
- Test authentication, authorization, session management, input validation, and business logic flaws.
- Identify vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), CSRF, SSRF, IDOR, Command Injection, XXE, and Remote Code Execution.
Secure Coding
- Review application code for common security weaknesses.
- Recommend secure coding practices based on OWASP Secure Coding Guidelines.
- Assist developers in understanding security vulnerabilities and remediation techniques.
- Participate in secure code reviews where applicable.
Bug Bounty & Security Research
- Apply methodologies used in bug bounty programs to identify security weaknesses.
- Research emerging vulnerabilities, attack techniques, and exploitation methods.
- Stay updated with the latest CVEs, threat intelligence, and security advisories.
Reporting & Documentation
- Prepare detailed VAPT reports with risk ratings, proof of concept (PoC), impact analysis, and remediation recommendations.
- Maintain proper documentation of assessments, findings, and testing methodologies.
Security Tools
Gain hands-on experience with industry-standard security tools such as:
- Burp Suite
- OWASP ZAP
- Nmap
- Metasploit
- Nikto
- SQLMap
- Gobuster
- ffuf
- Wireshark
- Nessus/OpenVAS
- Postman (API Testing)
Collaboration
- Work closely with development, DevOps, and security teams to remediate vulnerabilities.
- Participate in security discussions, reviews, and knowledge-sharing sessions.
Required Skills
- Good understanding of web application security concepts.
- Strong knowledge of the OWASP Top 10 and OWASP API Security Top 10.
- Understanding of common vulnerabilities such as:
- SQL Injection
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Server-Side Request Forgery (SSRF)
- Insecure Direct Object References (IDOR)
- Authentication and Authorization flaws
- Command Injection
- XML External Entity (XXE)
- File Inclusion vulnerabilities
- Knowledge of HTTP/HTTPS, REST APIs, cookies, sessions, and web technologies.
- Familiarity with Linux, networking fundamentals, and basic scripting (Python or Bash).
- Understanding of secure coding practices and secure software development lifecycle (SSDLC).
Qualifications
- Pursuing or recently completed a Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related field.
- Prior internship, lab experience, personal projects, CTF participation, or bug bounty experience is highly preferred.
- Robust analytical, communication, and problem-solving skills.
- Ability to work independently and as part of a team.
Preferred Certifications
Candidates with one or more of the following certifications will be preferred:
- Certified Ethical Hacker (CEH)
- eJPT (Junior Penetration Tester)
- PNPT (Practical Network Penetration Tester)
- CompTIA Security+
- CompTIA PenTest+
- Burp Suite Certified Practitioner
- Google Cybersecurity Professional Certificate
- ISC2 Certified in Cybersecurity (CC)
- PortSwigger Web Security Academy Practitioner Labs (Completed)
- Any Hack The Box, TryHackMe, or OffSec training certifications
Preferred Experience
- Hands-on bug bounty experience on platforms such as HackerOne, Bugcrowd, or Intigriti.
- Participation in Capture The Flag (CTF) competitions.
- Experience with Hack The Box, TryHackMe, PortSwigger Web Security Academy, or similar learning platforms.
- Knowledge of Git/GitHub and basic CI/CD security concepts.
What We Offer
- Hands-on exposure to real-world penetration testing engagements.
- Mentorship from experienced cybersecurity professionals.
- Opportunity to work on enterprise web applications, APIs, cloud environments, and infrastructure assessments.
- Learning and development in secure coding, offensive security, and vulnerability management.
- Potential full-time employment based on performance.
Pay: ₹15,203.47 - ₹18,904.69 per month
Work Location: In person
📌 VAPT Intern (India)
🏢 Cywarden
📍 India