11 Sep
|
CyberNX Technologies
|
Mumbai
11 Sep
CyberNX Technologies
Mumbai
Key Responsibilities:
- Perform VAPT engagements for web applications, APIs, mobile applications, internal and external networks, and cloud environments.
- Identify, validate, and assess vulnerabilities, misconfigurations, and business logic flaws.
- Prepare detailed assessment reports with technical findings, proof-of-concept evidence, risk ratings, business impact, and remediation recommendations.
- Communicate vulnerabilities and associated risks to technical and non-technical stakeholders.
- To perform remediation validation and re-testing to confirm the closure of identified issues.
- Stay updated with emerging threats, vulnerabilities, attack techniques, and current security trends.
Technical Skills :
- Strong understanding of networking concepts including TCP/IP, DNS, HTTP/HTTPS, routing, switching, VPNs, and firewalls
- Good knowledge of Operating Systems:o Linux (File system, Permissions, Basic commands) o Windows (Architecture, services, Registry basics)
- Strong understanding of web, mobile (Android/IOS) and API application architecture and security concepts.
- Knowledge of authentication and authorization mechanisms including sessions, cookies, JWT, OAuth, and SSO.
- Understanding of common attack vectors such as XSS, SQL injection, SSRF, CSRF, and IDOR.
- Understanding of REST, SOAP, GraphQL, and modern API architectures.
- Hands-on experience identifying vulnerabilities aligned with the OWASP Top 10 & SANS 25.
- Hands-on experience with tools: Burp Suite, Nessus, Metasploit, SQLmap, Postman, MobSF
- Strong knowledge in leveraging AI to automate VAPT processes and support security research and exploration.
- Strong troubleshooting skills with the ability to identify and resolve issues by understanding the client's setting.
Professional Skills
- Strong analytical and problem-solving abilities.
- Ability to think like an attacker while maintaining a risk-based approach. Strong technical documentation and report-writing skills.
- Strong verbal and written communication skills.
- Ability to work independently as well as collaboratively within a team environment.
- Strong attention to detail and commitment to delivering high-quality assessments.
- Ability to manage multiple engagements and meet project deadlines.
- Eagerness to learn new technologies, attack techniques, and security methodologies.
Qualifications
- Education o Bachelor’s degree in Computer Science, Information Technology, Cyber Security, or a related field.
Experience
- 2-4 years of hands-on experience in VAPT, Application Security, Offensive Security, or related cybersecurity domains. Internship, freelance, bug bounty, research, or lab-based experience will be considered valuable.
Required Skills
- Web VAPT
- Mobile VAPT
- API VAPT
- Network VA
Certifications (Preferred / Added Advantage)
- Certified Ethical Hacker (CEH)
- eJPT (eLearnSecurity Junior Penetration Tester)
- BSCP (Burp Suite Certified Practitioner)
- CompTIA Security PNPT (Practical Network Penetration Tester)
- CJCA (Certified Junior Cybersecurity Analyst)
- eCPPT (eLearnSecurity Certified Professional Penetration Tester)
- CPTS (Certified Penetration Testing Specialist) OSCP / OSCP (Offensive Security Certified Professional)
Pay: ₹800,000.00 - ₹900,000.00 per year
Benefits
- Health insurance
- Paid sick time
- Provident Fund
Application Question(s):
- How many years of hands-on VAPT experience do you have?
- Which VAPT tool have you used most extensively?
- Which authentication mechanisms have you worked with?
- Which operating system do you use for security testing?
- Do you hold any VAPT/security certification?
- Are you comfortable working from Mumbai?
- What is your current CTC ?
- What is your expected CTC?
- What is your notice period?
Work Location: In person
📌 Security Consultant (Mumbai)
🏢 CyberNX Technologies
📍 Mumbai