29 Aug
|
Rochasoft
|
Delhi
VAPT & SOC 2 Type II Security Tester
Company: TravellerTrack
Experience: 1–5 years
About TravellerTrack
TravellerTrack is an enterprise mobility and corporate transportation technology platform helping organizations manage employee transportation, spot rentals, approvals, vendors, drivers, and trip operations through a centralized digital platform.
As we expand our enterprise customer base, we are looking for an experienced VAPT & SOC 2 Type II Security Skilled to assess our platform and help us strengthen our security and compliance readiness.
Role Overview
We are looking for an experienced security tester/consultant who can independently conduct Vulnerability Assessment & Penetration Testing (VAPT) across our web applications, APIs, infrastructure, and relevant mobile applications, and support our SOC 2 Type II readiness and compliance requirements .
Key Responsibilities
- Conduct comprehensive VAPT of TravellerTrack's web application, APIs, mobile applications, and supporting infrastructure.
- Perform security testing based on OWASP Top 10, OWASP API Security Top 10, SANS, and industry best practices .
- Identify vulnerabilities including authentication, authorization, API security, injection, session management, access control, data exposure, business logic, and configuration issues.
- Perform vulnerability scanning and manual penetration testing.
- Assess cloud infrastructure, network configuration, databases, endpoints, and security controls where applicable.
- Validate identified vulnerabilities and provide clear evidence, risk ratings, and remediation recommendations.
- Conduct retesting after vulnerabilities are remediated.
- Review existing security policies, processes, access controls, logging, monitoring, backup, incident response, and change-management practices.
- Support TravellerTrack in preparing for SOC 2 Type II readiness/audit .
- Identify gaps against applicable SOC 2 Trust Services Criteria.
- Help establish practical security controls and documentation required for ongoing compliance.
- Provide professional reports suitable for sharing with enterprise customers and auditors.
Required Skills & Experience
- 1–5 years of experience in cybersecurity, VAPT, penetration testing, or information security.
- Strong hands-on experience with web application and API penetration testing .
- Knowledge of OWASP Top 10 and OWASP API Security Top 10.
- Experience testing REST APIs, authentication mechanisms, authorization controls, JWT/OAuth, and role-based access.
- Experience with tools such as Burp Suite, Nmap, Nessus/OpenVAS, Postman, Metasploit , or equivalent.
- Understanding of cloud security and common SaaS security architecture.
- Strong understanding of information security principles and risk management.
- Familiarity with SOC 2, ISO 27001, security policies, controls, and audit evidence .
- Ability to prepare professional VAPT reports with severity classification and remediation guidance.
Preferred Qualifications
- OSCP, CEH, CREST, CISSP, CISA, or equivalent certifications.
- Experience working with SaaS/technology companies.
- Previous experience supporting SOC 2 Type I/Type II audits.
- Experience working with enterprise customers and their security assessment requirements.
- Familiarity with AWS/Azure/GCP security controls.
- Experience with compliance frameworks such as ISO 27001, GDPR, or similar standards.
Deliverables The selected professional/agency will be expected to provide:
1. Comprehensive VAPT assessment.
2. Detailed vulnerability report with severity and evidence.
3. Executive-level security summary.
4. Remediation recommendations.
5. Retesting/validation after remediation.
6. SOC 2 readiness/gap assessment.
7. Recommendations for required security controls and documentation.
8. Support during security/compliance discussions where required.
What We Are Looking For We are looking for someone who can actually perform hands-on security testing and provide audit-ready documentation , rather than only conducting automated vulnerability scans.
If you have experience conducting VAPT for SaaS platforms and supporting organizations toward SOC 2 Type II readiness , we'd love to hear from you.
📌 Vapt tester (Delhi)
🏢 Rochasoft
📍 Delhi