19 Aug
|
Hexo Global Technologies
|
Thrissur
19 Aug
Hexo Global Technologies
Thrissur
We are looking for an experienced Vulnerability Assessment and Penetration Testing (VAPT) Engineer with 3+ years of experience in application and infrastructure security testing. The candidate will be responsible for identifying security vulnerabilities, performing penetration testing, preparing detailed reports, and supporting remediation activities.
Key Responsibilities
- Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, mobile applications, and infrastructure.
- Conduct black-box, grey-box, and white-box security testing based on project requirements.
- Identify and validate vulnerabilities such as:
- OWASP Top 10
- SQL Injection
- Cross-Site Scripting (XSS)
- Authentication and authorization issues
- Broken access control
- SSRF
- CSRF
- Security misconfiguration
- API vulnerabilities
- Business logic vulnerabilities
- Perform API security testing, including authentication, authorization, token validation, rate limiting, and API abuse scenarios.
- Conduct network and infrastructure VAPT, including server, network, firewall, and exposed services.
- Perform vulnerability scanning and manual validation using industry-standard tools.
- Analyze scan results and eliminate false positives through manual verification.
- Prepare detailed VAPT reports with vulnerability description, risk rating, evidence, business impact, and remediation recommendations.
- Work with development and infrastructure teams to support vulnerability remediation and retesting.
- Conduct security retesting to verify that identified vulnerabilities have been properly fixed.
- Maintain knowledge of emerging vulnerabilities, CVEs, attack techniques, and security best practices.
- Ensure testing activities comply with organizational security policies and applicable regulatory requirements.
Required Technical Skills
- Minimum 3 years of experience in VAPT / Cybersecurity / Application Security.
- Robust knowledge of OWASP Web and API Security.
- Experience with tools such as:
- Burp Suite
- OWASP ZAP
- Nmap
- Nessus / Qualys
- Metasploit
- SQLMap
- Postman
- Good understanding of:
- HTTP/HTTPS
- REST APIs
- JWT/OAuth/OIDC
- TCP/IP and networking
- Linux and Windows
- Web application architecture
- Databases and SQL
- Ability to perform manual penetration testing, not just automated vulnerability scanning.
- Basic scripting knowledge in Python, PowerShell, Bash, or similar languages is desirable.
- Knowledge of cloud security, preferably Azure/Oracle Cloud/AWS, would be an advantage.
Certifications – Preferred
- CEH
- OSCP
- eJPT
- CompTIA Security+
- CREST certifications
- Other recognized cybersecurity/VAPT certifications
Educational Qualification
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Key Competencies
- Strong analytical and problem-solving skills.
- Good understanding of security risks and their business impact.
- Ability to communicate vulnerabilities clearly to technical and business teams.
- Good documentation and report-writing skills.
- Ability to work independently as well as with development and infrastructure teams.
Pay: ₹30,000.00 - ₹40,000.00 per month
Ability to commute/relocate
- Thrissur, Kerala: Reliably commute or planning to relocate before starting work (Preferred)
Application Question(s):
- What is your current CTC?
- What is your Expected CTC?
Experience:
- VAPT Engineer: 3 years (Required)
Work Location: In person
📌 VAPT Engineer (Thrissur)
🏢 Hexo Global Technologies
📍 Thrissur