JOB SUMMARY
Lead and manage penetration testing engagements across web applications, APIs, external/internal networks, cloud environments, Active Directory, and wireless infrastructure. Serve as the primary technical lead for client engagements, oversee testing quality, mentor engineers, review reports, and provide strategic security recommendations. Based on the VAPT Team Lead responsibilities and structure from your reference JD.
TESTING AREAS & SPECIALIZATIONS
Application Security Testing
- Web Application Penetration Testing
- API Penetration Testing
- Mobile Application Security Testing
Network Security Testing
- External Network Penetration Testing
- Internal Network Penetration Testing
- Wireless Security Assessments
Identity & Access Security Testing
- Active Directory Security Assessments
- Microsoft Entra ID Security Assessments
- Hybrid Identity Security Assessments
- Okta Security Assessments
- CyberArk Security Assessments
Cloud Security Testing
- Microsoft Azure Security Assessments
- AWS Security Assessments
- Cloud Configuration Reviews
- Cloud Exposure Assessments
Social Engineering Assessments
- Phishing Campaign Assessments
- Spear Phishing Assessments
- Vishing (Voice Phishing) Assessments
- Smishing (SMS Phishing) Assessments
- User Awareness & Susceptibility Testing
Advanced Security Testing
- Assumed Breach Assessments
- Privilege Escalation Testing
- Lateral Movement Testing
- Attack Path Analysis
- Security Control Validation
OPERATIONAL RESPONSIBILITIES
- Lead end-to-end penetration testing engagements across web, API, network, cloud, wireless, Active Directory, Microsoft Entra ID, and social engineering assessments.
- Participate in client kickoff calls and technical discovery sessions to understand scope, objectives, and Rules of Engagement.
- Define testing methodologies, engagement plans, testing schedules, and Rules of Engagement.
- Communicate testing prerequisites, access requirements, connectivity requirements, test accounts,
and environmental dependencies to clients and internal stakeholders.
- Perform advanced exploitation and validation of identified vulnerabilities.
- Conduct attack path analysis, privilege escalation testing, assumed breach assessments, and lateral movement assessments.
- Provide technical guidance and oversight during assessment execution.
- Develop, review, and approve technical reports, risk ratings, executive summaries, and remediation recommendations.
- Present findings through technical readout sessions and executive-level presentations.
- Act as the primary technical point of contact during kickoff calls, status meetings, findings walkthroughs, and remediation discussions.
- Lead retesting activities and validate remediation effectiveness before final closure.
- Mentor and provide technical guidance to penetration testing engineers.
- Support proposal reviews, effort estimation, project scoping, and solution design activities.
- Develop testing standards, playbooks, reporting templates, and quality assurance processes.
- Drive continuous improvement initiatives and research emerging threats, attack techniques, and security tools.
EDUCATIONAL REQUIREMENTS, TOOLS & CERTIFICATIONS
Education: Diploma/bachelors degree in computer science, Information Technology or equivalent experience.
Experience:
- 610 years of penetration testing or VAPT experience.
- At least 2 years in a Lead or Senior Consultant role.
- Experience supporting US-based customers and working USA hours preferred.
Tools & Technologies:
- Primary VM Tools: Tenable, Rapid7 / InsightVM
- Patch / Remediation Tools: Tanium, Automox
- Risk & GRC: TruOps, Cyberfusion
- IAM / PAM: Okta, CyberArk
- Endpoint Security: CrowdStrike, SentinelOne
- Penetration Tools: Burp Suite Skilled, OWASP ZAP, Nmap, Metasploit, BloodHound, sqlmap, Nessus
- Scripting and Automation: Python, Powershell, Bash
- Reporting: Power BI, Excel, dashboards, executive reporting, ticketing workflows
Certifications:
- CEH, eJPT, eWPT, PNPT, Security+, OSCP (preferred)
📌 Penetration Testing Lead (Hyderabad)
🏢 Shi
📍 Hyderabad