27 Sep
|
Nameless
|
Bengaluru
27 Sep
Nameless
Bengaluru
We are seeking an experienced Principal Software Engineer - Cybersecurity (VAPT) to lead Vulnerability Assessment and Penetration Testing (VAPT) activities across enterprise applications, cloud platforms, infrastructure, and IoT/OT environments. The ideal candidate will drive security testing strategies, identify vulnerabilities, recommend remediation measures, and mentor security engineers while working closely with development, DevOps, and infrastructure teams.
Key Responsibilities
- Lead and execute comprehensive Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, mobile applications, cloud environments, and network infrastructure.
- Perform manual and automated penetration testing to identify security weaknesses and validate exploitability.
- Conduct source code reviews and secure architecture assessments.
- Support secure software development lifecycle (SSDLC) initiatives and DevSecOps integration.
- Assess cloud security posture across AWS, Azure, and GCP environments.
- Perform cybersecurity risk assessments and provide mitigation recommendations.
- Validate remediation efforts through re-testing and security audits.
- Develop security standards, guidelines,
and testing methodologies.
- Mentor and guide cybersecurity engineers and VAPT analysts.
- Collaborate with stakeholders to ensure compliance with industry standards such as ISO 27001, NIST, OWASP, IEC 62443, and GDPR.
Required Skills & Qualifications
- Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Security, or related field.
- 10+ years of experience in Cybersecurity, with at least 5 years focused on VAPT.
- Robust expertise in:
- Web Application Security Testing
- API Security Testing
- Network Penetration Testing
- Cloud Security Assessment
- Mobile Application Security
- Secure Code Review
- Threat Modeling
- Hands-on experience with tools such as:
- Burp Suite
- Nessus
- Nmap
- OWASP ZAP
- Metasploit
- Wireshark
- Kali Linux
- Qualys
- Strong understanding of OWASP Top 10, CWE, CVSS, MITRE ATT&CK;, and secure coding practices.
- Experience with CI/CD security integration and DevSecOps practices.
- Excellent analytical, problem-solving, and stakeholder management skills.
📌 Principal Software Engineer - Cybersecurity (VAPT) (Bengaluru)
🏢 Nameless
📍 Bengaluru