TymblHub

© 2026 TymblHub

VAPT consultant

Cyraac Services
Posted on
Cyraac Services logo

Experience
1 - 3 yrs
Salary (CTC)
₹4.4L - ₹6.4L
Job Location
Pune, India
Vacancy
1
Designation
Vapt Engineer
Job Type
Not specified

Job Description

Position: VAPT Consultant - AI and ML
Experience: 1-3 Years
Location: Pune


Job Summary

We are looking for a VAPT Consultant with 1-3 years of hands-on experience in application security and penetration testing. The ideal candidate should have experience in conducting security assessments for web applications, mobile applications, APIs, and cloud-native environments, with exposure to DevSecOps and emerging AI/LLM security concepts. The consultant will be responsible for identifying security vulnerabilities, validating security controls, and providing remediation recommendations while supporting secure software development practices.


Key Responsibilities

  • Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, mobile applications, and APIs.
  • Conduct security testing and validation for AI/ML applications and Large Language Model (LLM) integrations, including assessment of model behaviour, resilience, and common AI security risks.
  • Assist in reviewing AI/ML pipelines, training data security, and deployment configurations to identify potential security gaps.
  • Participate in secure architecture reviews and threat modelling exercises using methodologies such as STRIDE and MITRE ATT&CK.
  • Support DevSecOps initiatives by integrating security controls into CI/CD pipelines and promoting Shift-Left security practices.
  • Perform Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secrets detection, and Infrastructure as Code (IaC) security assessments.
  • Review containerized environments and Infrastructure as Code configurations for security best practices and vulnerabilities.
  • Work with development teams to promote secure coding standards and assist in vulnerability remediation and verification.
  • Prepare detailed security assessment reports with technical findings, business impact, risk ratings, and remediation recommendations.
  • Stay updated with the latest cybersecurity threats, attack techniques, and industry best practices.

Required Skills

  • 1-3 years of hands-on experience in Vulnerability Assessment and Penetration Testing (VAPT).
  • Good understanding of OWASP Top 10, OWASP API Security Top 10, and mobile application security concepts.
  • Hands-on experience with tools such as Burp Suite, OWASP ZAP, Nmap, Postman, and other security testing tools.
  • Basic knowledge of AI/ML and LLM security concepts, including prompt injection and model security fundamentals.
  • Understanding of DevSecOps practices, CI/CD pipelines, and security automation.
  • Familiarity with SAST, DAST, SCA, secrets detection, container security, and Infrastructure as Code (IaC) security.
  • Basic understanding of cloud platforms (AWS, Azure, or GCP), Docker, Kubernetes, networking, authentication mechanisms, and secure application development.
  • Strong analytical, troubleshooting, documentation, and communication skills.

Preferred Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
  • Security certifications such as CEH, eJPT, Security+, PNPT, or equivalent will be an added advantage.