27 Sep
|
Cyraac Services
|
Navi Mumbai
27 Sep
Cyraac Services
Navi Mumbai
Job Title:
Consultant
Experience: 2-4+ years with network penetration testing, VAPT and red teaming.
Note: Looking only for candidates who can join within 30 days.
We are looking for a highly skilled VAPT consultant with strong expertise in identifying complex security vulnerabilities across infrastructure, web, mobile.
Qualifications:
- BE/B. Tech with specialization in cyber security, MCA, M. Tech / masters in information security, or Forensics Analysis Knowledge.
- 2-4 years hands on experience working in VAPT, working for cybersecurity industry along with hands on experience in managing projects.
Experience & Certifications
- Experience ranging from 2 to 4 years in penetration testing, red teaming, or security consulting.
- Entry-level candidates should demonstrate solid fundamentals and hands-on exposure to tools.
- Mid-level candidates should demonstrate independent execution of penetration tests and technical reporting.
Preferred Certifications:
- Candidates having eJPT, eWPT, CCSP, CRTP, OSCP, PNPT are preferable.
Responsibilities
- Perform security assessments across IT infrastructure.
- Conduct reconnaissance, scanning, enumeration, exploitation, and post-exploitation activities.
- Perform vulnerability scanning using tools such as Nessus, OpenVAS, Qualys,
and validate findings manually.
- Conduct network penetration testing (firewalls, switches, routers, servers) and Active Directory exploitation.
- Perform web and API penetration testing using Burp Suite Pro, OWASP ZAP, SQLmap, and custom scripts.
- Develop and execute custom scripts/exploits (Python, PowerShell, Bash) where required.
- Document vulnerabilities with CVSS and EPSS scoring, proof of concept, and remediation recommendations.
- Prepare both technical reports and executive-level summaries.
- Ensure alignment with methodologies such as OWASP, PTES, OSSTMM, and MITRE ATT&CK.;
- Stay updated with emerging threats, exploits, and offensive security tools.
Required Technical Skills
- Strong understanding of networking (TCP/IP, DNS, HTTP/S, SSL/TLS, VPNs, Firewalls).
- Proficiency with penetration testing tools: Nmap, Burp Suite Pro, Metasploit, Nessus.
- Understanding of web application vulnerabilities (OWASP Top 10, API Security Top 10).
- Hands-on experience with exploitation techniques: privilege escalation, lateral movement, persistence.
- Knowledge of Active Directory attacks and defences.
- Scripting and automation skills in Python, Bash, and PowerShell.
📌 Network VAPT consultant (Navi Mumbai)
🏢 Cyraac Services
📍 Navi Mumbai