Cyber Security Analyst (Bengaluru)

Cyber Security Analyst (Bengaluru)

17 Sep
|
Quess Corp
|
Bengaluru

17 Sep

Quess Corp

Bengaluru

— Cyber Security Analyst

About the Role

Position: Cyber Security Analyst – Application & Infrastructure Security

Experience: 5–8 years

Reporting To: Head of IT

- Role Overview

We are looking for a Cyber Security Analyst (VAPT) responsible for identifying, assessing, prioritizing, and validating security vulnerabilities across the organization's applications, network, infrastructure, and technology environments. The role will work closely with application development, infrastructure, network, cloud, and technology teams to ensure identified vulnerabilities are appropriately assessed, remediated within agreed timelines, and independently validated through security retesting. The candidate should be able to translate technical vulnerabilities into business and technology risk, prioritize remediation based on impact, and provide practical guidance to technical teams on vulnerability closure.

Responsibilities

- 2. Key Responsibilities

A. Application Security Testing

- Perform security testing of applications across the SDLC.
- Conduct vulnerability assessments and security testing of:
- Web applications
- Mobile applications
- APIs
- Microservices
- Application infrastructure
- Review security testing reports and validate identified vulnerabilities.
- Assess vulnerabilities based on severity, exploitability, business criticality, exposure, and potential impact.
- Work with development teams to understand the root cause of vulnerabilities and recommend appropriate remediation approaches.
- Support security testing as part of application releases and major changes.

B. Network & Infrastructure Security Testing

- Perform and/or coordinate security assessments of:
- Servers
- Network devices
- Databases
- Cloud infrastructure
- Network segments
- Internet-facing infrastructure
- Review vulnerability assessment and penetration testing reports.
- Validate identified infrastructure and network vulnerabilities.




- Work with infrastructure/network teams to determine appropriate remediation actions.
- Assess vulnerabilities considering asset criticality, exposure, exploitability, and potential business impact.

C. Vulnerability Risk Assessment & Prioritization

- Establish risk-based prioritization of identified vulnerabilities.
- Prioritize remediation based on factors such as:
- Business criticality
- Internet exposure
- Data sensitivity
- Exploitability
- Availability of known exploits
- Potential business impact
- Compensating controls
- Recommend appropriate remediation timelines based on risk.
- Identify vulnerabilities requiring immediate escalation to management.
- Distinguish between technical severity and actual business risk.

D. Vulnerability Remediation & Closure

- Work closely with application, infrastructure, cloud, network, and database teams to drive vulnerability remediation.
- Provide technical guidance to teams on possible remediation approaches.
- Review proposed remediation plans and assess whether they adequately address the identified vulnerability.
- Track remediation progress and follow up on overdue or high-risk vulnerabilities.
- Support technical teams in resolving complex or recurring vulnerabilities.
- Escalate vulnerabilities that remain unresolved beyond agreed risk timelines.

E. Security Retesting & Validation

- Perform security retesting after remediation.
- Validate whether the vulnerability has been fully resolved.
- Confirm that remediation has not introduced current security issues.
- Review evidence provided by technical teams where appropriate.
- Formally confirm vulnerability closure only after satisfactory validation.




- Maintain appropriate records of testing, remediation, and closure evidence.

F. Security Governance & Reporting

- Maintain vulnerability registers and remediation status.
- Prepare periodic reports on:
- Open vulnerabilities
- Critical/high-risk vulnerabilities
- Aging vulnerabilities
- Remediation performance
- Recurring vulnerabilities
- Risk exceptions
- Provide security risk updates to Cyber Security leadership and relevant technology stakeholders.
- Support security audits, compliance assessments, and regulatory requirements

Qualifications

- 5. Qualifications & Experience
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related discipline.
- 5–8 years of experience in cybersecurity, VAPT, application security, infrastructure security.
- Experience working with application development and / or infrastructure teams.
- Experience managing vulnerability remediation through to closure.
- Experience in application, network, infrastructure, or cloud security testing.

Required Skills

- Technical Competencies The candidate should have good practical knowledge of:

- Application security and common web/API vulnerabilities.
- OWASP Top 10 and secure application development concepts.
- Vulnerability assessment and penetration testing methodologies.
- Network and infrastructure security fundamentals.
- Operating system, database, network, and cloud security concepts.
- Vulnerability management and risk-based prioritization.
- Common vulnerability scoring concepts such as CVSS and exploitability assessment.
- Security testing tools such as Burp Suite, Nessus/Tenable, Qualys, Nmap, or equivalent.
- Basic understanding of SIEM, EDR, WAF, firewall, IAM, and endpoint security technologies.
- Ability to interpret technical security reports and translate findings into actionable remediation requirements.

Hands-on expertise in security testing

📌 Cyber Security Analyst (Bengaluru)
🏢 Quess Corp
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cyber security analyst (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: cyber security analyst (bengaluru) / bengaluru