24 Aug
|
Cybersmithsecure
|
Mumbai
24 Aug
Cybersmithsecure
Mumbai
: VAPT Analyst
Job Title
VAPT Analyst (Vulnerability Assessment & Penetration Testing)
Employment Type
Intern / Trainee / FullTime
Department
Cyber Security and VAPT
Role Overview The VAPT Analyst is responsible for conducting hands-on vulnerability assessment and penetration testing across applications, infrastructure, identity systems, cloud environments, and networks.
This is a technical execution-focused role requiring real exploitation capability, attack simulation, and validation of security controls rather than reliance on automated scanning alone.
The role also supports red teaming and purple teaming initiatives, helping improve both offensive depth and defensive detection capabilities. Findings produced by this role directly influence risk posture, remediation priorities, and audit readiness.
Key Responsibilities
1. Web Application Security Testing
- Conduct black-box, gray-box, and authenticated penetration testing on web applications, portals, dashboards, and administrative interfaces.
- Identify and exploit vulnerabilities including:
- Broken authentication and authorization (IDOR, privilege escalation, access control bypass)
- Injection vulnerabilities (SQLi, command injection, SSTI, XXE)
- Session management flaws (JWT issues, CSRF, token misuse, session fixation)
- Test complex business logic flows such as workflows, approvals, role-based actions, and transaction handling.
- Manually validate findings to eliminate false positives and assess real-world exploitability.
1. Application & • API Security Testing
- Perform security testing of backend applications and APIs (REST, GraphQL, internal services).
- Assess API authentication, authorization, rate limiting, object-level access control, and data exposure risks.
- Test for insecure deserialization, mass assignment, improper input validation, and logic flaws.
- Evaluate application error handling, logging behavior, and trust boundaries.
1. Mobile Application Security (Android & iOS)
- Conduct static and dynamic analysis of Android and iOS applications.
- Assess security of API communication, SSL pinning, token storage, and local data handling.
- Test root/jailbreak detection mechanisms and bypass techniques.
- Identify insecure permissions, intents, deep links, and client-side logic flaws.
1. Infrastructure & • Internal Network Penetration Testing
- Perform penetration testing of internal networks, servers, and remote access infrastructure.
- Identify weak authentication mechanisms, exposed services, misconfigurations, and lateral movement paths.
- Simulate internal attacker scenarios to assess impact of compromised credentials or endpoints.
1. Active Directory & • Identity Security Testing
- Conduct security testing of Active Directory and Azure AD environments.
- Assess identity misconfigurations and excessive privileges that could lead to domain compromise.
1. Cloud Security Testing
- Perform security testing of cloud environments (AWS / Azure / GCP).
- Identify misconfigurations related to IAM, storage exposure, logging, monitoring, and network controls.
- Assess cloud-specific attack vectors including metadata abuse and over-permissive roles.
1. Network, Firewall & • Device Security Testing
- Test firewalls, VPNs, network segmentation, and exposed management interfaces.
- Identify weak ACLs, insecure rule configurations, and unnecessary exposure of services.
- Validate effectiveness of network security controls through controlled exploitation.
1. Red Teaming & • Purple Teaming Support
- Participate in red team exercises simulating real-world adversary behavior across multiple attack stages.
- Support purple teaming activities by collaborating with detection and SOC teams to improve visibility.
- Help develop attack playbooks, detection use cases, and post-exercise improvement recommendations.
1. Vulnerability Validation, Reporting & • Retesting
- Validate scanner findings and eliminate false positives through manual testing.
- Prepare detailed VAPT reports including:
- Risk-based severity ratings
- Exploitation steps and evidence
- Business impact explanation
- Remediation guidance mapped to best practices
- Perform retesting to confirm effective remediation and closure.
Required Skills & Qualifications Offensive Security & Testing Skills
- Solid hands-on experience in:
- Web application and API penetration testing
- Mobile application security (Android & iOS)
- Internal network and infrastructure pentesting
- Active Directory and identity security testing
- Cloud security testing (AWS / Azure / GCP)
Red Teaming & Purple Teaming
- Understanding of red teaming methodologies, attack chains, and adversary simulation.
- Experience supporting purple team engagements, including detection validation and feedback.
- Familiarity with MITRE ATT&CK; framework and mapping techniques.
Frameworks & Standards
- OWASP Top 10 (Web, API, Mobile)
- OWASP ASVS (preferred)
- Common Weakness Enumeration (CWE)
Platforms & Tools
- Tools: Burp Suite, Nmap, Nuclei, Metasploit, CrackMapExec, BloodHound
- Mobile tools: MobSF, Frida, JADX, APKTool
- Environments: Windows, Linux, Active Directory, Azure AD
- Cloud platforms: AWS / Azure / GCP
Certifications
- CEH
- OSCP, OSWE, CRTP, CRTO, or equivalent offensive security certifications
Experience Levels (Flexible) VAPT Intern (0-1 Years)
- Supports VAPT engagements by executing test cases, running tools, and identifying common vulnerabilities.
- Learns manual exploitation techniques and basic attack paths under supervision.
- Assists in report preparation, evidence capture, and vulnerability retesting.
VAPT Analyst (1-4 Years)
- Independently executes end-to-end VAPT engagements across web, API, infrastructure, and cloud scopes.
- Performs manual exploitation, attack chaining, and business impact assessment.
- Produces high-quality, client-ready reports and supports remediation discussions.
Senior VAPT Analyst (4+ Years)
- Leads complex VAPT, red team, and purple team engagements involving multiple attack vectors.
- Designs advanced attack paths and mentors junior analysts.
- Reviews reports for technical accuracy, risk justification, and audit defensibility.
What Success Looks Like
- Vulnerabilities are accurately identified, validated, and risk-rated
- Critical and high-risk issues are clearly exploitable and reproducible
- Remediation efforts result in verified, sustainable fixes
- Attack surface and repeat findings reduce measurably over time
Why Join Us
- Opportunity to design core operational systems
- High ownership and visibility
- Flexibility in experience level
- Handson exposure to real project workflows and automation
📌 VAPT Analyst (Mumbai)
🏢 Cybersmithsecure
📍 Mumbai