19 Sep
|
TAXOSMART
|
Mumbai
TaxoSmart is looking for a hands-on Ethical Hacker / VAPT Engineer to perform Vulnerability Assessment and Penetration Testing of our web applications, APIs, servers, mobile application and infrastructure, primarily supporting enterprise and BFSI applications.
Key Responsibilities
- Perform Web Application, API and Network VAPT.
- Identify, validate and document security vulnerabilities.
- Conduct manual testing based on OWASP Top 10 and OWASP API Security Top 10.
- Test authentication, authorization, session management, access control, injection, XSS, CSRF, SSRF, file upload, business logic and security misconfiguration.
- Perform vulnerability assessment of Linux/Windows servers, NGINX, Tomcat, databases and network services.
- Prepare professional VAPT reports, PoCs, evidence and remediation recommendations.
- Perform vulnerability retesting and closure validation.
- Work with Development, QA, DevOps and Infrastructure teams for remediation.
- Support BFSI customer security assessments, audits and compliance requirements.
Required Skills
- CEH certification Mandatory
- 0–5 years practical VAPT / Ethical Hacking experience.
- Strong knowledge of OWASP Top 10.
- Hands-on experience with Burp Suite, Kali Linux, Nmap, Nessus/OpenVAS, Metasploit, OWASP ZAP, SQLMap and Postman.
- Strong understanding of HTTP/HTTPS, TCP/IP, DNS and networking.
- Experience in Web Application and REST API security testing.
- Good understanding of authentication, authorization and access-control vulnerabilities.
- Basic scripting knowledge in Python / Bash / JavaScript / SQL.
- Positive technical documentation and communication skills.
Preferred
- CEH Practical / OSCP / eJPT / PNPT.
- Experience with BFSI/Banking applications.
- Knowledge of Java/Spring Boot, React, REST APIs, NGINX, Tomcat and Oracle.
- Experience with SAST/DAST, Secure SDLC and ISO 27001.
📌 Vapt Auditor (Mumbai)
🏢 TAXOSMART
📍 Mumbai