Cybersecurity Consultant – VAPT & Red Teaming****Experience - 3 to 5 yearsAbout the Role
We are looking for a passionate and experienced Cybersecurity Consultant to join our team. The ideal candidate should have strong hands-on expertise in offensive security, vulnerability assessments, penetration testing, and red teaming . If you thrive in challenging security environments and enjoy solving complex security problems, we would love to connect with you.
Key Responsibilities
- Conduct Vulnerability Assessment & Penetration Testing (VAPT) across web applications, APIs, networks, infrastructure, and external attack surfaces .
- Perform web application security assessments , including authentication, authorization, session management, input validation, and business logic testing.
- Conduct API penetration testing covering REST, SOAP, GraphQL, authentication mechanisms, access controls, and data exposure.
- Execute infrastructure VAPT across servers, network devices, firewalls, cloud environments, and enterprise infrastructure.
- Participate in red teaming and adversary simulation engagements , including reconnaissance, attack-path identification, exploitation, and post-exploitation activities.
- Perform authorized post-exploitation activities to assess the impact of identified vulnerabilities and demonstrate potential business risks.
- Conduct lateral movement assessments to identify opportunities for unauthorized access across systems, network segments, and enterprise environments.
- Identify, analyze, validate, and responsibly document security vulnerabilities , including proof of concept and supporting evidence.
- Prepare detailed technical reports covering findings, severity, business impact, attack paths, remediation recommendations, and revalidation results.
- Collaborate with clients and internal teams to communicate technical findings and provide actionable security improvement recommendations.
- Stay updated on emerging vulnerabilities, exploitation techniques, attack frameworks, and industry security practices .
Required Skills & Experience
- 3–5 years of hands-on experience in VAPT, offensive security, cybersecurity consulting , or a related field.
- Strong practical experience in web application, API, and infrastructure penetration testing .
- Positive understanding of networking and security concepts , including TCP/IP, DNS, HTTP/HTTPS, authentication, firewalls, and network segmentation.
- Hands-on experience with reconnaissance, vulnerability identification, exploitation, post-exploitation, and lateral movement techniques in authorized assessment environments.
- Familiarity with tools such as Burp Suite, Nmap, Metasploit, Nuclei, BloodHound, Impacket , and relevant red teaming frameworks.
- Working knowledge of OWASP Top 10, OWASP API Security Top 10 , and common vulnerability classification standards such as CVSS and CWE .
- Ability to analyze complex security issues , develop attack scenarios, and provide practical remediation guidance.
- Strong technical documentation, communication, and client-facing skills .
- Ability to work independently and collaboratively across multiple security engagements.
Preferred Certifications
- OSCP
- CRTP
- CRTO or other recognized red teaming certifications
- CREST or equivalent offensive security certifications
What We Offer
- Exposure to diverse cybersecurity consulting and offensive security engagements .
- Opportunities to work on challenging VAPT, red teaming, and security assessment projects .
- A collaborative environment focused on continuous learning and professional growth .*
📌 Cybersecurity Consultant – VAPT & Red Teaming (Delhi)
🏢 sarc
📍 Delhi