01 Oct
|
C3iHub, IIT Kanpur
|
Kanpur
01 Oct
C3iHub, IIT Kanpur
Kanpur
About the RoleAs a Vulnerability Assessment and Penetration Testing (VAPT) Engineer, you will play a crucial role in evaluating and strengthening the security posture of the organization’s IT infrastructure, applications, and networks.Your primary responsibilities will include identifying and addressing security vulnerabilities through detailed assessments and penetration testing. You will work closely with cross-functional teams to enhance security measures and safeguard systems against potential threats.ResponsibilitiesConduct Vulnerability Assessments
- Perform detailed vulnerability assessments on internal and external systems, networks, and applications.
- Utilize automated tools and manual techniques to identify security weaknesses.
Perform Penetration Testing
- Execute penetration tests on IT infrastructure, web applications, mobile platforms, and network components.
- Simulate cyber-attacks to evaluate the effectiveness of security measures.
Analyze and Report Findings
- Analyze assessment and testing results to identify potential vulnerabilities and risks.
- Prepare comprehensive reports with actionable recommendations for remediation.
- Communicate findings effectively to both technical and non-technical stakeholders.
Collaborate with Teams
- Work closely with VAPT, development, and operations teams to prioritize and remediate identified vulnerabilities.
- Assist in implementing security controls and solutions.
Maintain Documentation
- Develop and maintain documentation related to assessment methodologies, findings, and remediation recommendations.
- Ensure all documentation remains updated and easily accessible.
Stay Current with Cybersecurity Trends
- Stay updated with emerging cybersecurity threats, vulnerabilities, and industry best practices.
- Incorporate new knowledge and techniques into testing activities to improve effectiveness.
EligibilityEducational Background
- Bachelor’s degree in Computer Science,
Information Technology, Cybersecurity, or a related field.
Technical Skills
- Strong understanding of network protocols, operating systems, and web technologies.
- Proficiency with security testing tools such as Nessus, Nmap, Burp Suite, Metasploit, and similar platforms.
- In-depth knowledge of IT security standards and frameworks such as OWASP, NIST, and SANS Top 25.
- Familiarity with the OSI model, TCP/IP model, and core networking concepts.
- Hands-on experience in manual penetration testing and security assessments.
Experience
- 4+ years of relevant experience in VAPT or cybersecurity-related roles.
Desired Eligibility
- Broad knowledge of security technologies related to applications, databases, networks, servers, Active Directory, and desktops.
- Experience with IoT/OT security will be considered an added advantage.
- Deep understanding of embedded protocols such as UART, I2C, SPI, JTAG, and SWD.
- Experience with radio protocol attacks involving BLE, Wi-Fi, LoRa, DSP, and SDR.
Relevant Certifications
- Certifications such as CEH (Certified Ethical Hacker), OSCP (Offensive Security Certified Skilled), or equivalent certifications are preferred.
- Experience in scripting and programming is beneficial.
- Experience with penetration testing simulations such as Hack The Box or Capture The Flag (CTF) exercises.
- Hands-on experience with commercial and open-source tools/frameworks including Burp Suite, Metasploit, Core Impact, Scapy, AppScan, WebInspect, Qualys, Nessus, Nmap, SQLmap, and OWASP ZAP.
TravelTravel may be required across the country for project execution, monitoring, assessments, testing activities, and coordination with geographically distributed teams, as and when required.CommunicationSubmit a cover letter summarising your experience in relevant technologies and software, along with your resume and latest passport-size photograph.
Pay: ₹328,043.04 - ₹1,423,994.28 per year
Work Location: In person
📌 VAPT Engineer (Kanpur)
🏢 C3iHub, IIT Kanpur
📍 Kanpur