Job Description
About the Role
We are looking for an experienced Cybersecurity Specialist Cyber Security, Enterprise Risk Management to identify, assess, and help remediate security vulnerabilities across our applications, networks, and infrastructure, while also owning end-to-end security engagements and coordinating with stakeholders across the organization. The ideal candidate combines strong hands-on penetration testing skills with the ability to manage projects, communicate risk to business teams, and drive engagements from scoping to closure.
Key Responsibilities — Technical
- Conduct vulnerability assessments and penetration testing on web applications, mobile applications, APIs, networks, and AI/ML applications
- Perform manual exploitation and validate findings from automated scanning tools to eliminate false positives
- Prepare detailed technical reports with risk ratings, evidence (PoCs), and remediation recommendations
- Stay current with the latest CVEs, attack techniques, and threat intelligence
- Contribute to internal security tooling, scripts, and testing methodologies
- Ensure testing aligns with OWASP, NIST, PTES, OSSTMM or SANS methodologies
Key Responsibilities — Engagement & Stakeholder Management
- Own end-to-end security engagements, from scope definition through remediation closure
- Define assessment scope and strategy based on business criticality and regulatory requirements
- Plan and prioritize assessments across the portfolio, balancing risk, compliance deadlines, and business needs
- Manage multiple concurrent projects and ensure timely delivery of engagements
- Review and approve security reports, ensuring quality, accuracy, and consistency before client/stakeholder delivery
- Coordinate with internal teams (development, DevOps, IT) and external vendors/third-party testers
- Track remediation and closure timelines, following up with relevant owners
- Conduct risk discussions with business and technology teams to align severity and remediation priority
- Present security findings and risk posture to management and leadership
- Manage escalations related to findings, delays, or engagement issues
- Handle resource planning and allocation across engagements
- Contribute to the development of security policies and standards
- Align security initiatives and priorities with broader organizational objectives
Required Skills & Qualifications
- 3–5 years of hands-on experience in VAPT / penetration testing
- Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related discipline
- Strong knowledge of OWASP Top 10, SANS Top 25, and common attack vectors
- Proficiency with tools such as Burp Suite, Nmap, Metasploit, Nessus/Qualys, Wireshark, Nikto, sqlmap, OWASP ZAP
- Experience with network penetration testing (internal/external), web/mobile app testing, API security testing and AI security.
- Familiarity with scripting/programming (Python, Bash, PowerShell) for automation and custom exploit development
- Understanding of cloud security (AWS/Azure/GCP) is a plus
- Good understanding of TCP/IP, firewalls, IDS/IPS, and network protocols
- Demonstrated experience managing security engagements or projects, including stakeholder coordination and timeline ownership
- Strong report-writing skills, with experience reviewing/approving reports from other testers
Preferred Certifications
- OSCP (Offensive Security Certified Professional)
- CEH (Certified Ethical Hacker)
- CompTIA Security+/PenTest+
- GPEN / GWAPT (GIAC)
Soft Skills
- Strong stakeholder management and executive communication skills
- Ability to translate technical risk into business language for leadership
- Analytical mindset with attention to detail
- Ability to manage multiple engagements and competing priorities independently
- Strong verbal and written communication for client-facing and management reporting
- Comfortable handling escalations and driving resolution under time pressure
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
