27 Sep
|
Certbar security
|
Mumbai
27 Sep
Certbar security
Mumbai
Position Title: Security Analyst
nLocation: Surat / Mumbai
nExperience: 1–3 Years
nEmployment Type: Full-time
nJob Summary
nWe are looking for a Security Analyst with 1–3 years of hands-on experience in Vulnerability Assessment, Penetration Testing (VAPT), and security testing . The candidate will be responsible for identifying security vulnerabilities, validating security risks, documenting findings, and supporting remediation activities across applications, APIs, networks, and infrastructure.
nKey Responsibilities
n
n
- Perform manual and automated Vulnerability Assessment and Penetration Testing (VAPT) .
n
- Conduct security assessments of web applications, APIs, mobile applications, networks, and infrastructure .
n
- Identify, validate, and document security vulnerabilities and misconfigurations.
n
- Perform manual testing to identify vulnerabilities that may not be detected by automated scanners.
n
- Perform vulnerability scanning, manual validation, exploitation, and proof-of-concept (PoC) development where applicable.
n
- Analyse vulnerability severity, business impact, and associated risks.
n
- Prepare detailed technical and executive security assessment reports , including vulnerability description, risk rating, evidence/PoC, reproduction steps, impact, and remediation recommendations.
n
- Conduct retesting to validate that reported vulnerabilities have been properly remediated.
n
- Work with development, infrastructure,
and IT teams to understand and communicate security findings.
n
- Participate in client discussions, security assessment walkthroughs, and remediation discussions when required.
n
- Stay updated on new vulnerabilities, CVEs, attack techniques, and cybersecurity trends .
n
- Follow established security testing methodologies, standards, and best practices.
n
nRequired Skills &
Qualifications
n
n
- 1–3 years of hands-on experience in Cybersecurity, VAPT, Penetration Testing, Application Security, or a related role.
n
- Good understanding of Web Application, API, Network, and Infrastructure Security .
n
- Strong understanding of OWASP Top 10 and common vulnerability classes.
n
- Good knowledge of CVEs, CWEs, CVSS , and vulnerability risk assessment.
n
- Good understanding of networking fundamentals , including TCP/IP, DNS, HTTP/HTTPS, SSL/TLS, and common network protocols.
n
- Working knowledge of Windows and Linux operating systems .
n
- Hands-on experience with security tools such as Burp Suite, Nmap, Nessus/OpenVAS, Metasploit, Wireshark, OWASP ZAP , or equivalent.
n
- Ability to perform both tool-assisted and manual security testing .
n
- Good analytical and problem-solving skills.
n
- Robust technical documentation and report-writing skills.
n
- Good verbal and written communication skills.
n
- Ability to work independently and manage multiple security assessments effectively.
n
n
📌 Security Analyst (Mumbai)
🏢 Certbar security
📍 Mumbai