We are seeking a highly skilled Vulnerability Assessment & Penetration Testing (VAPT) Engineer to join our Cyber Security team. The ideal candidate will be responsible for conducting comprehensive security assessments of web applications, APIs, and enterprise applications to identify vulnerabilities and recommend remediation measures. The role requires solid expertise in offensive security testing, application security, and secure coding practices.
Key Responsibilities :
Vulnerability Assessment & Penetration Testing:
- Perform Web Application VAPT and identify security vulnerabilities across business-critical applications.
- Conduct API Security Assessments and penetration testing of REST/SOAP APIs.
- Execute manual and automated security testing using industry-standard tools.
- Analyze application architecture and identify potential security weaknesses.
- Perform authentication, authorization, session management, input validation, and business logic testing.
- Validate vulnerability fixes and conduct re-testing activities.
Application Security:
- Assess applications against OWASP Top 10 Web Application Security Risks.
- Assess APIs against OWASP API Security Top 10.
- Identify and report vulnerabilities such as:
Reporting & Stakeholder Management:
- Prepare detailed technical and executive VAPT reports.
- Provide risk ratings, remediation recommendations, and proof-of-concept findings.
- Collaborate with development, DevOps, and infrastructure teams to address security vulnerabilities.
- Conduct security awareness sessions and share best practices with development teams.
Required Skills
- Web Application VAPT
- API VAPT
- Application Security Testing
- OWASP Top 10 (Web Applications)
- OWASP API Security Top 10
- Burp Suite Professional
- OWASP ZAP
- Manual Penetration Testing
- Security Assessment & Reporting
- Secure Coding Principles
- Threat Modeling
- Vulnerability Management
- 3 to 8 years of relevant experience in Web Application Security and Penetration Testing.
- Hands-on experience conducting VAPT engagements independently.
- Practical experience with Burp Suite, OWASP ZAP, Nmap, Metasploit, and related security tools.
- Experience working with SDLC, DevSecOps, and secure application development practices is preferred.
Educational Qualification:
- Bachelor's Degree in Computer Science, Information Security, Information Technology, or related field.
- Relevant Cyber Security certifications will be an added advantage.