21 Sep
|
ASM - Process Automation
|
India
21 Sep
ASM - Process Automation
India
About the Role
We are looking for a skilled Penetration Tester / VAPT Engineer to assess the security posture of our IT and OT environments through hands-on offensive security testing.
The candidate will be responsible for identifying, validating, documenting, and reporting security vulnerabilities, as well as providing clear remediation recommendations.
Key Responsibilities
- Conduct internal and external penetration testing across IT and OT networks.
- Perform web application security testing aligned with the OWASP Top 10.
- Assess Windows Active Directory environments for security misconfigurations.
- Perform privilege escalation and lateral movement testing.
- Conduct password security testing, including controlled brute-force simulations.
- Perform vulnerability assessments using Nessus, Qualys, and OpenVAS.
- Manually validate vulnerabilities and eliminate false positives.
- Prepare professional VAPT reports with CVSS scoring and prioritized remediation recommendations.
- Present security findings to technical teams and leadership.
- Maintain a findings and risk register and track remediation through closure.
- Re-test vulnerabilities after remediation to confirm closure.
Required Qualifications
- Bachelor's degree in IT, Computer Science, Cybersecurity, or a related field.
- 2–4 years of dedicated hands-on VAPT experience.
- Robust understanding of TCP/IP, routing, DNS, DHCP, VPN, and VLAN from an offensive-security perspective.
- Good knowledge of Windows and Linux security internals.
- Hands-on experience with penetration-testing and vulnerability-assessment tools.
Mandatory Certification
Candidates must hold at least one offensive-security certification:
- CEH – Certified Ethical Hacker
- OSCP – Offensive Security Certified Professional
- eJPT – eLearnSecurity Junior Penetration Tester
Technical Skills
- VAPT: Kali Linux, Metasploit, Burp Suite, Nmap
- Vulnerability Scanning: Nessus, Qualys
- Scripting: PowerShell, Bash, Python
- Packet Analysis: Wireshark
- Web application security and OWASP Top 10
- Active Directory security
- IT/OT network security
Preferred Certifications
OT/ICS-specific offensive-security certification is an advantage, such as:
- GICSP
- ISA/IEC 62443
- GRID
- CompTIA PenTest+
Apply Now: If you have hands-on penetration-testing experience and are interested in working across IT and OT security environments, we encourage you to apply.
The technical scope above is based on your uploaded JD.
Pay: From ₹8,000,000.00 per year
Benefits:
- Flexible schedule
- Paid sick time
- Provident Fund
Work Location: In person
📌 Penetration Tester / VAPT Engineer – Offensive Security (India)
🏢 ASM - Process Automation
📍 India