21 Aug
|
CyberSigma Consulting Services
|
Noida
21 Aug
CyberSigma Consulting Services
Noida
Job Location: Noida (In office)
Experience: 1–2 Years
Employment Type: Full-Time
Job Summary
We are looking for a skilled and motivated VAPT (Vulnerability Assessment and Penetration Testing) Tester with 1–2 years of hands-on experience in application and infrastructure security testing. The ideal candidate should have a solid understanding of penetration testing methodologies, OWASP Top 10, and common security vulnerabilities. You will be responsible for identifying, validating, and reporting security weaknesses across web applications, mobile applications, APIs, networks, and cloud environments.
Key Responsibilities
- Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, mobile applications, internal/external networks, and cloud environments.
- Conduct manual and automated security testing to identify vulnerabilities.
- Validate security findings and eliminate false positives.
- Prepare comprehensive VAPT reports with technical findings, business impact, risk ratings, proof of concept, and remediation recommendations.
- Perform vulnerability verification after remediation.
- Execute network and infrastructure security assessments.
- Identify OWASP Top 10, API Security Top 10, and business logic vulnerabilities.
- Assist development and IT teams in understanding and fixing security issues.
- Stay updated with emerging threats, vulnerabilities, and attack techniques.
- Participate in security assessments,
audits, and client discussions when required.
Required Skills
- Good understanding of Web Application Security.
- Knowledge of OWASP Top 10 and OWASP API Security Top 10.
- Experience in manual penetration testing.
- Understanding of network security concepts.
- Basic knowledge of Linux and Windows environments.
- Familiarity with authentication, authorization, session management, and cryptography.
- Knowledge of HTTP/HTTPS protocols and REST APIs.
- Strong analytical and problem-solving skills.
- Good technical report writing and communication skills.
Required Tools
- Burp Suite
- Nmap
- Nessus
- OWASP ZAP
- Nikto
- Metasploit Framework
- Postman
- SQLMap
- Wireshark
- MobSF (Preferred)
Preferred Qualifications
- CEH, eJPT, PNPT, Security+, or similar cybersecurity certification.
- Knowledge of Mobile Application Security Testing (Android/iOS).
- Basic understanding of Cloud Security (AWS, Azure, or GCP).
- Familiarity with scripting languages such as Python, Bash, or PowerShell is an advantage.
Educational Qualification
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Experience
- 1–2 years of hands-on experience in:
- Web Application VAPT
- API Security Testing
- Network Penetration Testing
- Infrastructure Security Assessment
- Security Report Preparation and Remediation Validation
📌 VAPT Tester (1–2 Years Experience) (Noida)
🏢 CyberSigma Consulting Services
📍 Noida