29 Aug
|
Clearwater
|
India
Location: Clearwater Pune, WFO
Experience: 1–3 years
Employment Type: Full-time
Department: Cybersecurity / Information Security
Reporting To: Senior Consultant / Team Lead
About The Role
Clearwater is looking for a Junior Consultant –
- Vulnerability Assessment, Penetration Testing (VAPT) &
- Red Teaming to join our consulting services team.
The role will support the delivery of vulnerability assessments, penetration testing, application and infrastructure security assessments, and red team engagements for clients across different technology environments. The ideal candidate should have a solid foundation in cybersecurity, networking, operating systems and common security testing methodologies, along with a willingness to continuously learn and develop offensive security skills.
Key Responsibilities
Vulnerability Assessment &
- Penetration Testing
- Assist in conducting vulnerability assessments and penetration tests across:
- Web applications and APIs
- Mobile applications
- Network and infrastructure environments
- Cloud environments
- Internal and external networks
- Wireless environments, where applicable
- Perform reconnaissance, enumeration, vulnerability identification and validation.
- Identify and safely validate security weaknesses using manual and automated techniques.
- Assist with exploitation and post-exploitation activities under approved engagement scopes.
- Conduct security testing in accordance with established methodologies such as OWASP, PTES and NIST, as applicable.
- Analyse scan results and distinguish genuine vulnerabilities from false positives.
Red Teaming
- Support red team and adversary simulation engagements under the guidance of senior team members.
- Assist with reconnaissance, attack-path identification, initial access, privilege escalation, lateral movement and other approved activities.
- Develop an understanding of adversary tactics, techniques and procedures (TTPs), aligned with frameworks such as MITRE ATT&CK; and regulatory compliance requirements such as HIPAA, HITRUST, PCI DSS, SOC2, CMMC.
- Assist in evaluating security controls, detection capabilities and potential attack paths.
- Document technical findings with clear evidence and reproduction steps.
- Prepare professional vulnerability assessment, penetration testing and red team reports.
- Provide risk ratings, business impact and remediation recommendations for identified vulnerabilities.
- Maintain accurate POC, testing notes, evidence and supporting documentation.
- Participate in client discussions and technical walkthroughs
- Stay current with emerging vulnerabilities, exploits, attack techniques and cybersecurity trends.
- Research new tools, techniques and methodologies relevant to offensive security.
- Build and maintain practical skills through labs, CTFs and security research.
- Contribute to internal knowledge bases, testing methodologies and reusable security-testing resources.
Required Skills &
- Qualifications
- Bachelor's degree or equivalent qualification in Computer Science, Information Technology, Cybersecurity or a related discipline.
- 1–3 years of experience in cybersecurity, VAPT, security testing or a related technical role.
- Good understanding of:
- Networking fundamentals and Windows and Linux operating systems
- Web application architecture and common security vulnerabilities
- Authentication, authorization and session management
- Basic scripting/programming concepts
- Cybersecurity principles and attack methodologies
- Familiarity with OWASP Top 10 and common web application vulnerabilities.
- Basic understanding of MITRE ATT&CK; and AI Security.
- Hands-on familiarity with tools such as Burp Suite, Nmap, Tenable Nessus/ OpenVAS, Wireshark, Metasploit, Kali Linux,
OWASP ZAP or similar tools.
- Strong analytical and problem-solving skills.
- Good written and verbal communication skills.
- One or more of Certifications such as CEH, eJPT, PNPT, Security+, OSCP or equivalent.
- Exposure to cloud security testing across AWS, Azure or GCP.
- Basic knowledge of Active Directory security and Windows domain environments.
- Familiarity with scripting using Python, PowerShell or Bash.
- Exposure to API, mobile application or container security testing.
- Participation in platforms such as Hack The Box, TryHackMe, PortSwigger Web Security Academy or CTF competitions.
- Basic understanding of security controls such as EDR, SIEM, firewalls, IDS/IPS and WAF.
- Strong curiosity and passion for offensive cybersecurity.
- Ability to think like both an attacker and a defender.
- Ability to work independently as well as within a consulting team.
- Professional approach to handling sensitive client information.
Disclaimer: The above statements are intended to describe the general nature and level of work being performed by people assigned to this position. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of colleagues in the role. All colleagues may be required to perform duties outside of their normal responsibilities from time to time, as needed. Clearwater is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. Please inform Clearwater/Redspin’s Recruiting team if you need any assistance completing any forms or to otherwise participating in the application process.
Mental/Physical Requirements: Fast paced environment handling multiple demands. Must be able to exercise appropriate judgment as necessary. Requires a high level of initiative and independence. Excellent written and oral communication skills required. Requires the ability to use a personal computer for extended periods of time.
📌 Junior Consultant – Vulnerability Assessment, Penetration Testing & Red Teaming (India)
🏢 Clearwater
📍 India