- Perform manual VAPT across web, API, mobile, network and cloud environments, going beyond automated scans
- Validate and chain vulnerabilities to demonstrate real business impact with proof of concept
- Deliver clear, risk-rated technical and executive reports with practical remediation guidance
- Conduct retests and work with client teams until findings are verified as closed
- Support red teaming, attack surface management and compliance-driven testing (CERT-In, RBI, SEBI)
- Keep methodologies current and ensure deliverables pass QRM review on time
Key Requirements
- Bachelor's degree in Computer Science, IT, Engineering or a related field
- 2–6 years of hands-on experience in VAPT / penetration testing
- Proficiency with tools such as Burp Suite, Nmap, Metasploit, Nessus / Qualys, Nuclei, MobSF, Frida and Wireshark
- Strong understanding of web, API, mobile and network attack techniques
- Working knowledge of Linux and Windows environments, Active Directory and common network protocols
- Scripting ability in Python, Bash or PowerShell
- Robust report-writing skills