04 Aug
|
Cyraac Services
|
Pune
04 Aug
Cyraac Services
Pune
Position: VAPT Consultant - AiML and Devops
Experience: 1-3 Years
Location: Pune
Job Summary
We are looking for a VAPT Consultant with 1-3 years of hands-on experience in application security and penetration testing. The ideal candidate should have experience in conducting security assessments for web applications, mobile applications, APIs, and cloud-native environments, with exposure to DevSecOps and emerging AI/LLM security concepts. The consultant will be responsible for identifying security vulnerabilities, validating security controls, and providing remediation recommendations while supporting secure software development practices.
Key Responsibilities
- Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, mobile applications, and APIs.
- Conduct security testing and validation for AI/ML applications and Large Language Model (LLM) integrations, including assessment of model behaviour, resilience, and common AI security risks.
- Assist in reviewing AI/ML pipelines, training data security, and deployment configurations to identify potential security gaps.
- Participate in secure architecture reviews and threat modelling exercises using methodologies such as STRIDE and MITRE ATT&CK.;
- Support DevSecOps initiatives by integrating security controls into CI/CD pipelines and promoting Shift-Left security practices.
- Perform Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secrets detection, and Infrastructure as Code (IaC) security assessments.
- Review containerized environments and Infrastructure as Code configurations for security best practices and vulnerabilities.
- Work with development teams to promote secure coding standards and assist in vulnerability remediation and verification.
- Prepare detailed security assessment reports with technical findings, business impact, risk ratings, and remediation recommendations.
- Stay updated with the latest cybersecurity threats, attack techniques, and industry best practices.
Required Skills
- 1-3 years of hands-on experience in Vulnerability Assessment and Penetration Testing (VAPT).
- Valuable understanding of OWASP Top 10, OWASP API Security Top 10, and mobile application security concepts.
- Hands-on experience with tools such as Burp Suite, OWASP ZAP, Nmap, Postman, and other security testing tools.
- Basic knowledge of AI/ML and LLM security concepts, including prompt injection and model security fundamentals.
- Understanding of DevSecOps practices, CI/CD pipelines, and security automation.
- Familiarity with SAST, DAST, SCA, secrets detection, container security, and Infrastructure as Code (IaC) security.
- Basic understanding of cloud platforms (AWS, Azure, or GCP), Docker, Kubernetes, networking, authentication mechanisms, and secure application development.
- Strong analytical, troubleshooting, documentation, and communication skills.
Preferred Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
- Security certifications such as CEH, eJPT, Security+, PNPT, or equivalent will be an added advantage.
📌 VAPT consultant (Pune)
🏢 Cyraac Services
📍 Pune