VAPT consultant

Cyraac Services
Posted on
Cyraac Services logo

Experience
1 - 3 yrs
Salary (CTC)
₹4.4L - ₹6.4L
Job Location
Pune, India
Vacancy
1
Designation
Vapt Engineer
Job Type
Not specified

Job Description

Position: VAPT Consultant - AI and ML
Experience: 1-3 Years
Location: Pune


Job Summary

We are looking for a VAPT Consultant with 1-3 years of hands-on experience in application security and penetration testing. The ideal candidate should have experience in conducting security assessments for web applications, mobile applications, APIs, and cloud-native environments, with exposure to DevSecOps and emerging AI/LLM security concepts. The consultant will be responsible for identifying security vulnerabilities, validating security controls, and providing remediation recommendations while supporting secure software development practices.


Key Responsibilities

  • Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, mobile applications, and APIs.
  • Conduct security testing and validation for AI/ML applications and Large Language Model (LLM) integrations, including assessment of model behaviour, resilience, and common AI security risks.
  • Assist in reviewing AI/ML pipelines, training data security, and deployment configurations to identify potential security gaps.
  • Participate in secure architecture reviews and threat modelling exercises using methodologies such as STRIDE and MITRE ATT&CK.
  • Support DevSecOps initiatives by integrating security controls into CI/CD pipelines and promoting Shift-Left security practices.
  • Perform Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secrets detection, and Infrastructure as Code (IaC) security assessments.
  • Review containerized environments and Infrastructure as Code configurations for security best practices and vulnerabilities.
  • Work with development teams to promote secure coding standards and assist in vulnerability remediation and verification.
  • Prepare detailed security assessment reports with technical findings, business impact, risk ratings, and remediation recommendations.
  • Stay updated with the latest cybersecurity threats, attack techniques, and industry best practices.

Required Skills

  • 1-3 years of hands-on experience in Vulnerability Assessment and Penetration Testing (VAPT).
  • Good understanding of OWASP Top 10, OWASP API Security Top 10, and mobile application security concepts.
  • Hands-on experience with tools such as Burp Suite, OWASP ZAP, Nmap, Postman, and other security testing tools.
  • Basic knowledge of AI/ML and LLM security concepts, including prompt injection and model security fundamentals.
  • Understanding of DevSecOps practices, CI/CD pipelines, and security automation.
  • Familiarity with SAST, DAST, SCA, secrets detection, container security, and Infrastructure as Code (IaC) security.
  • Basic understanding of cloud platforms (AWS, Azure, or GCP), Docker, Kubernetes, networking, authentication mechanisms, and secure application development.
  • Strong analytical, troubleshooting, documentation, and communication skills.

Preferred Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
  • Security certifications such as CEH, eJPT, Security+, PNPT, or equivalent will be an added advantage.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.