Vapt tester (Delhi)

Vapt tester (Delhi)

29 Aug
|
Rochasoft
|
Delhi

29 Aug

Rochasoft

Delhi

VAPT & SOC 2 Type II Security Tester

Company: TravellerTrack

Experience: 1–5 years

About TravellerTrack

TravellerTrack is an enterprise mobility and corporate transportation technology platform helping organizations manage employee transportation, spot rentals, approvals, vendors, drivers, and trip operations through a centralized digital platform.

As we expand our enterprise customer base, we are looking for an experienced VAPT & SOC 2 Type II Security Skilled to assess our platform and help us strengthen our security and compliance readiness.

Role Overview

We are looking for an experienced security tester/consultant who can independently conduct Vulnerability Assessment & Penetration Testing (VAPT) across our web applications, APIs, infrastructure, and relevant mobile applications, and support our SOC 2 Type II readiness and compliance requirements .

Key Responsibilities

- Conduct comprehensive VAPT of TravellerTrack's web application, APIs, mobile applications, and supporting infrastructure.
- Perform security testing based on OWASP Top 10, OWASP API Security Top 10, SANS, and industry best practices .
- Identify vulnerabilities including authentication, authorization, API security, injection, session management, access control, data exposure, business logic, and configuration issues.
- Perform vulnerability scanning and manual penetration testing.
- Assess cloud infrastructure, network configuration, databases, endpoints, and security controls where applicable.
- Validate identified vulnerabilities and provide clear evidence, risk ratings, and remediation recommendations.
- Conduct retesting after vulnerabilities are remediated.
- Review existing security policies, processes, access controls, logging, monitoring, backup, incident response, and change-management practices.
- Support TravellerTrack in preparing for SOC 2 Type II readiness/audit .
- Identify gaps against applicable SOC 2 Trust Services Criteria.
- Help establish practical security controls and documentation required for ongoing compliance.




- Provide professional reports suitable for sharing with enterprise customers and auditors.

Required Skills & Experience
- 1–5 years of experience in cybersecurity, VAPT, penetration testing, or information security.
- Strong hands-on experience with web application and API penetration testing .
- Knowledge of OWASP Top 10 and OWASP API Security Top 10.
- Experience testing REST APIs, authentication mechanisms, authorization controls, JWT/OAuth, and role-based access.
- Experience with tools such as Burp Suite, Nmap, Nessus/OpenVAS, Postman, Metasploit , or equivalent.
- Understanding of cloud security and common SaaS security architecture.
- Strong understanding of information security principles and risk management.
- Familiarity with SOC 2, ISO 27001, security policies, controls, and audit evidence .
- Ability to prepare professional VAPT reports with severity classification and remediation guidance.

Preferred Qualifications
- OSCP, CEH, CREST, CISSP, CISA, or equivalent certifications.
- Experience working with SaaS/technology companies.
- Previous experience supporting SOC 2 Type I/Type II audits.
- Experience working with enterprise customers and their security assessment requirements.
- Familiarity with AWS/Azure/GCP security controls.
- Experience with compliance frameworks such as ISO 27001, GDPR, or similar standards.

Deliverables The selected professional/agency will be expected to provide:
1. Comprehensive VAPT assessment.
2. Detailed vulnerability report with severity and evidence.
3. Executive-level security summary.
4. Remediation recommendations.
5. Retesting/validation after remediation.
6. SOC 2 readiness/gap assessment.
7. Recommendations for required security controls and documentation.
8. Support during security/compliance discussions where required.

What We Are Looking For We are looking for someone who can actually perform hands-on security testing and provide audit-ready documentation , rather than only conducting automated vulnerability scans.

If you have experience conducting VAPT for SaaS platforms and supporting organizations toward SOC 2 Type II readiness , we'd love to hear from you.

📌 Vapt tester (Delhi)
🏢 Rochasoft
📍 Delhi

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: vapt tester (delhi) / delhi

Subscribe to this job alert:

Get the latest job offers by email for: vapt tester (delhi) / delhi