Job Description
GRC Responsibilities
Assist in conducting risk assessments, gap analyses, and readiness reviews against ISO 27001 / NIST / SOC 2
Draft and update information security policies, procedures, and control documentation
Support internal and external audits: evidence collection, observations tracking, NCR closure
Monitor compliance dashboards and track regulatory change management activities
Maintain asset inventories and support BCP / DR planning exercises
VAPT Responsibilities
Conduct vulnerability assessments and penetration tests on web applications, APIs, mobile apps, and internal networks
Use standard tools (Burp Suite, Nmap, OpenVAS, Nessus, Metasploit) for structured testing
Document findings with clear reproduction steps, CVSS risk ratings, and remediation guidance
Participate in configuration reviews for servers, firewalls, and cloud infrastructure
Support red team or social engineering simulations under supervised engagements
Required Skills & Tools
Working knowledge of OWASP Top 10, CWE, CVE databases, and CVSS scoring methodology
Experience with vulnerability scanning platforms and interpreting automated reports
Familiarity with ISO 27001 control framework, risk registers, and audit evidence preparation
Understanding of network protocols: TCP/IP, DNS, HTTP/S, SSL/TLS and common attack vectors
Basic scripting in Python or Bash for task automation
Burp Suite, Nmap, OpenVAS, Nessus, Metasploit
Required Certifications
CEH (Certified Ethical Hacker) OR OSCP (Offensive Security Certified Professional)
ISO 27001 Lead Auditor (LA) or Lead Implementer (LI)
Education / Qualifications
B.E. / B.Tech / M.Tech / MCA in Computer Science, Information Technology, or Cybersecurity
23 years of hands-on experience covering both GRC and VAPT deliverables
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
