13 Aug
|
Soffit Infrastructure Services
|
India
13 Aug
Soffit Infrastructure Services
India
Job Title: VAPT Engineer – 3+ Years Experience
Job Summary:
We are looking for an experienced Vulnerability Assessment and Penetration Testing (VAPT) Engineer with 3+ years of experience in application and infrastructure security testing. The candidate will be responsible for identifying security vulnerabilities, performing penetration testing, preparing detailed reports, and supporting remediation activities.
Key Responsibilities
· Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, mobile applications, and infrastructure.
· Conduct black-box, grey-box, and white-box security testing based on project requirements.
· Identify and validate vulnerabilities such as:
o OWASP Top 10
o SQL Injection
o Cross-Site Scripting (XSS)
o Authentication and authorization issues
o Broken access control
o SSRF
o CSRF
o Security misconfiguration
o API vulnerabilities
o Business logic vulnerabilities
· Perform API security testing, including authentication, authorization, token validation, rate limiting, and API abuse scenarios.
· Conduct network and infrastructure VAPT, including server, network, firewall, and exposed services.
· Perform vulnerability scanning and manual validation using industry-standard tools.
· Analyze scan results and eliminate false positives through manual verification.
· Prepare detailed VAPT reports with vulnerability description, risk rating, evidence, business impact, and remediation recommendations.
· Work with development and infrastructure teams to support vulnerability remediation and retesting.
· Conduct security retesting to verify that identified vulnerabilities have been properly fixed.
· Maintain knowledge of emerging vulnerabilities, CVEs, attack techniques, and security best practices.
· Ensure testing activities comply with organizational security policies and applicable regulatory requirements.
Required Technical Skills
· Minimum 3 years of experience in VAPT / Cybersecurity / Application Security.
· Strong knowledge of OWASP Web and API Security.
· Experience with tools such as:
o Burp Suite
o OWASP ZAP
o Nmap
o Nessus / Qualys
o Metasploit
o SQLMap
o Postman
· Positive understanding of:
o HTTP/HTTPS
o REST APIs
o JWT/OAuth/OIDC
o TCP/IP and networking
o Linux and Windows
o Web application architecture
o Databases and SQL
· Ability to perform manual penetration testing, not just automated vulnerability scanning.
· Basic scripting knowledge in Python, PowerShell, Bash, or similar languages is desirable.
· Knowledge of cloud security, preferably Azure/Oracle Cloud/AWS, would be an advantage.
Certifications – Preferred
· CEH
· OSCP
· eJPT
· CompTIA Security+
· CREST certifications
· Other recognized cybersecurity/VAPT certifications
Educational Qualification
· Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Pay: Up to ₹800,000.00 per year
Application Question(s):
- What is your current ctc?
- What is your Expected ctc?
- How many years of expereince?
Work Location: In person
📌 VAPT Engineer (India)
🏢 Soffit Infrastructure Services
📍 India