Senior VAPT Engineer

Yamaha Motor Solutions India Pvt Ltd
Posted on
Yamaha Motor Solutions India Pvt Ltd logo

Experience
5 - 10 yrs
Job Location
Faridabad, India
Vacancy
1
Designation
Vapt Engineer
Job Type
Not specified

Job Description

Core Security Assessment Skills

  • Hands-on experience in Web Application, Mobile Application (iOS Android), API, Host, Network, Active Directory, Cloud, and Security Device Vulnerability Assessment Penetration Testing.
  • Proficient in conducting both Manual and Automated Security Testing aligned with OWASP, SANS, and industry best practices.
  • Experience performing Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST).
  • Strong understanding of OWASP Top 10, OWASP Mobile Top 10, OWASP API Security Top 10, and common attack vectors.
  • Experience in authenticated and unauthenticated security assessments.
  • Knowledge of vulnerability validation, exploitation techniques, and remediation verification.
  • Understanding of attack surface analysis and threat modeling methodologies.

Security Tools Expertise

Experience with one or more of the following tools:

Burp Suite Professional, Nessus, HCL AppScan, Qualys, OWASP ZAP, Nmap, Wireshark, Postman, Kali Linux, Metasploit, BloodHound, CrackMapExec (NetExec), Impacket Toolkit.

Technical Knowledge

  • API Security Assessment (REST and SOAP APIs).
  • Network Infrastructure and Security Device VAPT.
  • Operating System and Host Security Assessments.
  • Active Directory Security Assessment and Internal Network Penetration Testing.
  • Understanding of Web Technologies including HTML, JavaScript, HTTP/HTTPS, Cookies, Sessions, Authentication and Authorization Mechanisms.
  • Knowledge of Cryptographic Concepts including Encryption, Hashing, PKI, Digital Certificates, TLS/SSL, and Secure Communication Protocols.
  • Experience configuring authenticated scans using Basic Authentication, Form-Based Authentication, Cookies, Tokens, JWT, OAuth, OpenID Connect, and SSO mechanisms.
  • Understanding of Threat Modeling methodologies such as STRIDE.
  • Knowledge of Identity and Access Management (IAM) concepts and solutions.
  • Understanding of Secure Software Development Lifecycle (SSDLC) principles.

Nice-to-Have Skills

Red Teaming concepts and tools such as Metasploit, Cloud Security Assessment and VAPT in AWS and Microsoft Azure environments, Container and Kubernetes Security, Familiarity with SIEM platforms and security monitoring solutions, Secure Code Review, Scripting knowledge in Python, PowerShell, Bash, or similar languages.

Preferred Certifications

Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), GIAC Penetration Tester (GPEN), CREST Registered Penetration Tester (CRT), Practical Network Penetration Tester (PNPT), Certified Red Team Professional (CRTP), CompTIA Security+, Offensive Security Web Expert (OSWE).

Security Assessment Testing

  • Perform vulnerability assessments and penetration testing of web applications, mobile applications, APIs, networks, Active Directory environments, cloud platforms, servers, and security devices.
  • Execute manual and automated testing techniques to identify, validate, and exploit vulnerabilities to assess business impact.
  • Conduct authenticated and unauthenticated security assessments.
  • Assess application security controls, authentication mechanisms, authorization models, session management, and cryptographic implementations.
  • Perform attack surface analysis and threat modeling activities.
  • Conduct vulnerability validation and remediation verification activities.

Reporting Remediation

  • Prepare comprehensive VAPT reports with technical findings, risk ratings, proof-of-concepts, and remediation recommendations.
  • Collaborate with Development, Infrastructure, Cloud, and Security teams to support vulnerability remediation and re-validation.
  • Provide security guidance and best practices to stakeholders.
  • Present assessment findings to technical and management teams.

Research Continuous Improvement

  • Stay updated on emerging threats, vulnerabilities, attack techniques, and security technologies.
  • Contribute to the development and enhancement of internal security methodologies, tools, scripts, and processes.
  • Support security audits, compliance assessments, and governance initiatives.
  • Research new attack vectors and offensive security techniques.

Stakeholder Management

  • Coordinate with internal teams, external vendors, and third-party assessors during security engagements.
  • Participate in incident response investigations and post-incident security reviews.
  • Support Quality Assurance Group (QAG) activities related to security auditing and IT process compliance.
  • Support security awareness sessions, training programs, and technical presentations.

Personal Attributes

  • Strong analytical and problem-solving skills.
  • Passion for cybersecurity and ethical hacking.
  • Excellent verbal and written communication skills.
  • Ability to create and deliver security awareness sessions, training, and presentations.
  • Strong customer engagement and stakeholder management skills.
  • Ability to work independently and collaboratively within cross-functional teams.
  • High attention to detail and commitment to quality deliverables.
  • Ability to effectively communicate technical findings to both technical and non-technical stakeholders.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.