VAPT Lead (Ahmedabad)

VAPT Lead (Ahmedabad)

05 Sep
|
Adani Group
|
Ahmedabad

05 Sep

Adani Group

Ahmedabad

Purpose/Objective

The VAPT Lead will be responsible for leading the vulnerability assessment and penetration testing (VAPT) initiatives across the organization.
This role involves managing the entire VAPT process, from planning and scoping assessments to executing and reporting on findings.
The VAPT Lead will collaborate with other cybersecurity teams to identify, assess, and mitigate vulnerabilities in the organization’s infrastructure, applications, and network environments.
The VAPT Lead is a key player in improving the security posture of the organization by providing in-depth security testing and actionable insights to prevent potential cyber threats.

Key Responsibilities of Role

VAPT Lead Vulnerability Assessment and Penetration Testing (VAPT): Lead and manage comprehensive VAPT activities across the organization’s infrastructure, applications, and network systems.
Plan and scope penetration tests and vulnerability assessments based on organizational needs and potential risks.
Perform vulnerability scanning, manual testing, and exploitations of identified vulnerabilities.
Conduct internal and external penetration testing to identify potential weaknesses in systems, applications, and networks.
Perform risk assessments and prioritize remediation based on business impact and severity.
Team Leadership and Management: Lead and mentor a team of security professionals, including penetration testers and vulnerability assessors.
Allocate resources effectively for different VAPT projects and ensure timely execution of testing activities.
Provide coaching, guidance, and training to junior team members to foster a growth environment and enhance skill sets.
Ensure adherence to best practices, policies, and ethical standards while conducting penetration testing.
Collaboration with Other Cybersecurity Teams: Work closely with security operations, incident response, and other teams to share findings and ensure alignment between security testing and overall security strategy.
Provide security recommendations for remediation based on findings from VAPT assessments and assist with the implementation of mitigation strategies.
Collaborate with development teams, IT, and system administrators to support vulnerability remediation efforts.
Reporting and Documentation:



Prepare comprehensive reports on VAPT findings, including vulnerabilities discovered, risk assessments, exploitability, and recommended remediations.
Provide both high-level executive summaries and detailed technical reports for different stakeholders (management, technical teams, etc.
).
Track the progress of vulnerabilities remediation and provide regular updates to senior leadership.
Security Standards and Compliance: Ensure that penetration testing and vulnerability assessments follow relevant security frameworks, industry standards, and compliance regulations (e.
g.
, OWASP, NIST, ISO 27001, GDPR).
Perform regular assessments of compliance requirements and security controls to ensure adherence to security policies.
Contribute to the development of organizational policies and guidelines related to vulnerability management, penetration testing, and overall security best practices.
Security Tools and Technologies: Lead the selection, deployment, and management of security tools and technologies used for vulnerability assessments, penetration testing, and exploit research (e.
g.
, Nessus, Burp Suite, Metasploit, Nmap, etc.
).
Continuously evaluate and improve the use of security tools to enhance testing capabilities and ensure efficiency.
Threat Intelligence and Research: Stay up-to-date with the latest cybersecurity threats, attack methods, vulnerabilities, and industry trends.
Conduct research to identify emerging security threats and testing techniques and incorporate them into testing methodologies.
Maintain knowledge of advanced attack techniques and tools to simulate real-world attacks and improve testing accuracy.
Continuous Improvement: Continuously improve testing methodologies, processes, and workflows to increase the effectiveness of VAPT efforts.
Develop and implement new strategies for proactive vulnerability management and penetration testing based on lessons learned and evolving threats.




Advocate for continuous improvement of the organization’s overall security posture based on VAPT findings and industry best practices.
Incident Response and Forensics: Support the incident response team in analyzing vulnerabilities related to security incidents, providing insights into the potential exploitation of discovered vulnerabilities.
Assist in the development of incident response plans, particularly in relation to vulnerability management and exploitation scenarios.
Key Stakeholders - Internal Chief Information Security Officer (CISO) Business Unit Heads and Department Heads Information Security and IT teams Risk Management Teams Security Operations Team Engineering & Development Teams Incident Response Teams Key Stakeholders - External Regulatory Authorities Third-Party Service Providers

Technical Competencies

Application Security Management-CYS,Cybersecurity Program & Strategy Management-CYS,IT Support & Infrastructure Security-CYS,Identity & Access Management-CYS,Network Security & Perimeter Defense-CYS,Operational Technology & Industrial Control System Security-CYS,Research and Innovation-CYS,Security Assessment and Testing-CYS

Qualifications and Experience

Educational Qualification: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Advanced degree (e.
g.
, Master's, MBA) in Cybersecurity, Information Assurance, or a relevant discipline is highly desirable.
Certification: Certifications: Relevant certifications such as Offensive Security Certified Qualified (OSCP), Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), or GIAC Penetration Tester (GPEN) are highly preferred.
Extensive experience with vulnerability scanning tools (e.
g.
, Nessus, OpenVAS), web application testing tools (e.
g.
, Burp Suite), and penetration testing frameworks.
Deep knowledge of common web and network vulnerabilities (e.
g.
, SQL injection, XSS, buffer overflows, etc.
) and security tools.
Experience with scripting and automation (e.
g.
, Python, Bash, PowerShell) is a plus.
Work Experience (Range of years): 5+ years of hands-on experience in penetration testing, vulnerability assessment, and ethical hacking.

📌 VAPT Lead (Ahmedabad)
🏢 Adani Group
📍 Ahmedabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: vapt lead (ahmedabad) / ahmedabad

Subscribe to this job alert:

Get the latest job offers by email for: vapt lead (ahmedabad) / ahmedabad