01 Oct
|
Briskinfosec Technology and Consulting private
|
Chennai
01 Oct
Briskinfosec Technology and Consulting private
Chennai
Preferred Qualifications
About the Role
We are looking for a VAPT Analyst to join our cybersecurity team and contribute to Vulnerability Assessment, Penetration Testing, Bug Bounty, and Security Research activities. The role involves identifying, validating, exploiting, and documenting security vulnerabilities across web applications, APIs, mobile applications, networks, infrastructure, and cloud environments.
Candidates with 0–5 years of experience are welcome. Practical exposure through professional experience, internships, CTFs, bug bounty programs, security research, or cybersecurity projects will be considered.
Key Responsibilities
- Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, mobile applications, networks, infrastructure, and cloud environments.
- Conduct security assessments using both automated tools and manual testing techniques.
- Perform reconnaissance, enumeration, vulnerability discovery, exploitation, and post-exploitation activities where applicable.
- Identify, validate, and document vulnerabilities with appropriate severity, risk ratings, technical evidence, and remediation recommendations.
- Test applications against OWASP Top 10, OWASP API Security Top 10, and relevant security testing methodologies.
- Perform manual testing to identify vulnerabilities that may not be detected by automated scanners.
- Prepare detailed technical VAPT reports and executive summaries, including vulnerability description, impact, evidence, reproduction steps, severity, and remediation.
- Conduct vulnerability re-validation after remediation.
- Participate in client discussions and technical walkthroughs to explain findings and remediation requirements.
- Participate in authorized bug bounty and responsible vulnerability disclosure programs.
- Perform reconnaissance and attack-surface discovery for in-scope bug bounty assets.
- Identify and validate vulnerabilities such as IDOR/BOLA,
authentication and authorization flaws, business logic vulnerabilities, XSS, SQL Injection, SSRF, CSRF, API vulnerabilities, and security misconfigurations.
- Develop appropriate Proof of Concept (PoC) and clearly document vulnerability reproduction steps.
- Research emerging vulnerabilities, CVEs, exploits, attack techniques, and security trends.
- Participate in CTF challenges, security research, and internal knowledge-sharing activities.
- Collaborate with application, development, infrastructure, and security teams to understand application architecture and security requirements.
- Contribute to improving internal VAPT methodologies, checklists, and security testing processes.
Required Skills:
- Good understanding of Web Application Security and common vulnerabilities.
- Strong knowledge of OWASP Top 10 and familiarity with OWASP API Security Top 10.
- Understanding of REST APIs, authentication, authorization, session management, input validation, and API security.
- Valuable understanding of TCP/IP, DNS, HTTP/HTTPS, SSL/TLS, ports, and network protocols.
- Working knowledge of Linux and Windows operating systems.
- Understanding of VAPT methodologies and vulnerability management.
- Ability to analyze vulnerabilities and understand their technical and business impact.
- Good analytical, troubleshooting, and problem-solving skills.
- Strong technical documentation and communication skills.
- Practical exposure to bug bounty, CTFs, security research, or cybersecurity labs is an advantage.
Qualifications:
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Relevant certifications such as eJPT, PJPT, CEH, Security+, OSCP/OSCP+, CRTP, or equivalent are an added advantage.
- Candidates with recognized bug bounty submissions, acknowledged vulnerabilities, CVEs, CTF achievements, security research, or relevant cybersecurity projects will be preferred.
Pay: Up to ₹600,000.00 per year
Benefits
- Health insurance
- Provident Fund
Work Location: In person
📌 Security Engineer (Chennai)
🏢 Briskinfosec Technology and Consulting private
📍 Chennai