VAPT Security Engineer (Kolkata)

VAPT Security Engineer (Kolkata)

06 Aug
|
ARC Document Solutions
|
Kolkata

06 Aug

ARC Document Solutions

Kolkata

Job Title: VAPT Security Engineer

Location: Kolkata (Work from Office)
Experience: 3+ Years
Employment Type: Full-Time

About the Role

We are looking for a highly motivated VAPT Security Engineer to join our Product Security team. In this role, you will be responsible for identifying and mitigating security risks across our applications, infrastructure, cloud environments, and enterprise systems. You will work closely with Engineering, DevOps, and Product teams to strengthen our security posture by conducting in-depth security assessments, penetration testing, and vulnerability management.

If you are passionate about offensive security, ethical hacking, cloud security, and securing modern applications, we'd love to hear from you.

Key Responsibilities

- Perform Vulnerability Assessment and Penetration Testing (VAPT) on:
- Web Applications
- REST APIs
- Mobile Applications (Android/iOS)
- Internal & External Networks
- Cloud Infrastructure (AWS/Azure/GCP)
- Containers and Kubernetes environments

- Conduct both automated and manual penetration testing using industry-standard methodologies.
- Identify, exploit (where authorized), validate, and document security vulnerabilities.
- Assess applications against OWASP Top 10, API Security Top 10, CWE, SANS Top 25, and industry best practices.
- Perform authenticated and unauthenticated security assessments.
- Execute network, wireless, and infrastructure penetration testing.
- Conduct source code reviews and secure code assessments where applicable.
- Perform configuration reviews for servers, firewalls, cloud resources, and operating systems.
- Collaborate with developers and DevOps engineers to remediate vulnerabilities and perform re-validation after fixes.
- Prepare detailed technical and executive-level VAPT reports with risk ratings, business impact, proof of concept, and remediation guidance.




- Track vulnerabilities from identification through closure.
- Stay updated on emerging threats, CVEs, exploit techniques, zero-day vulnerabilities, and attack vectors.

Red Teaming Responsibilities (Preferred)

- Participate in Red Team exercises and adversary simulations.
- Conduct privilege escalation, lateral movement, and post-exploitation assessments in controlled environments.
- Perform phishing simulations and security awareness testing.
- Test detection capabilities of security monitoring solutions (EDR, SIEM, IDS/IPS).
- Simulate real-world attack scenarios to evaluate organizational resilience.

Cloud Security Responsibilities

- Assess cloud infrastructure security across AWS, Azure, or Google Cloud Platform.
- Review IAM policies, security groups, network segmentation, storage configurations, and cloud-native security controls.
- Perform security assessments for containers (Docker), Kubernetes clusters, and CI/CD pipelines.
- Validate cloud compliance against security best practices.

Compliance & Governance

Experience supporting security assessments aligned with one or more of the following frameworks is desirable:

- ISO 27001
- SOC 2
- PCI-DSS
- NIST Cybersecurity Framework
- CIS Benchmarks
- GDPR
- HIPAA (preferred)

Required Technical Skills

- Strong hands-on experience in Vulnerability Assessment and Penetration Testing.
- Expertise in:
- Web Security Testing
- API Security Testing
- Network Penetration Testing
- Infrastructure Security Assessment

- Strong understanding of:





- OWASP Top 10
- OWASP API Security Top 10
- MITRE ATT&CK; Framework
- CVSS
- Common Vulnerabilities and Exposures (CVE)

Security Tools

Hands-on experience with multiple tools such as:

- Burp Suite Professional
- OWASP ZAP
- Nessus
- Nmap
- Metasploit
- SQLMap
- Nikto
- Wireshark
- Acunetix
- MobSF
- Gobuster
- Dirsearch
- Hydra
- BloodHound
- Impacket
- CrackMapExec (preferred)

Programming & Scripting

Good working knowledge of one or more of the following:

- Python
- Bash
- PowerShell
- JavaScript
- SQL

Ability to automate repetitive security tasks will be an added advantage.

Operating Systems

Hands-on experience with:

- Linux
- Windows Server
- Active Directory
- Networking Concepts
- TCP/IP
- DNS
- HTTP/HTTPS
- VPN
- Firewalls
- Reverse Proxies

Preferred Certifications

Candidates holding one or more of the following certifications will have an advantage:

- OSCP
- PNPT
- CEH
- eJPT
- CompTIA Security+
- CRTP
- AWS Security Specialty
- Azure Security Engineer Associate

Qualifications

- Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related discipline.
- 3+ years of hands-on experience in VAPT, penetration testing, or offensive security.

What We're Looking For

- Robust analytical and problem-solving skills.
- Passion for ethical hacking and offensive security.
- Excellent report writing and communication skills.
- Ability to work independently and collaboratively in a fast-paced product environment.
- Continuous learner with a keen interest in emerging cyber threats and up-to-date attack techniques.

If you're passionate about cybersecurity, enjoy solving complex security challenges, and want to make a meaningful impact by securing innovative products and cloud platforms, we'd love to hear from you.

📌 VAPT Security Engineer (Kolkata)
🏢 ARC Document Solutions
📍 Kolkata

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: vapt security engineer (kolkata) / kolkata

Subscribe to this job alert:

Get the latest job offers by email for: vapt security engineer (kolkata) / kolkata