Experience
2 - 6 yrs
Job Location
Bengaluru, India
Vacancy
1
Designation
Vapt Engineer
Job Type
ONSITE
Job Description
Job Summary
We are seeking a skilled VAPT Engineer responsible for performing comprehensive Vulnerability Assessment and Penetration Testing across web applications, mobile applications, APIs, network infrastructure, cloud environments, wireless networks, and thick client applications. The candidate should possess strong knowledge of cybersecurity principles, vulnerability identification, exploitation techniques, remediation validation, and report preparation while adhering to industry standards and best practices.
Key Responsibilities Web Application Security Testing - Perform Web Application VAPT using OWASP WSTG methodology.
- Identify OWASP Top 10 vulnerabilities.
- Manual vulnerability verification.
- Authentication Authorization Testing.
- Session Management Testing.
- Business Logic Testing.
- Input Validation Testing.
- File Upload Security Testing.
- API Security Testing.
- Source Code Review (basic understanding).
- Android Security Assessment.
- iOS Security Assessment.
- OWASP Mobile Top 10 Testing.
- Reverse Engineering Basics.
- Certificate Pinning Validation.
- Local Storage Assessment.
- Secure Communication Testing.
- REST API Security Testing.
- SOAP API Testing.
- GraphQL Security Assessment.
- JWT Token Testing.
- OAuth Authentication Testing.
- Rate Limiting Validation.
- Authorization Testing.
- Business Logic Testing.
- External Network Assessment.
- Internal Network Assessment.
- Firewall Security Review.
- Switch Security Assessment.
- Router Security Assessment.
- VPN Security Testing.
- Wireless Security Assessment.
- Active Directory Assessment.
- Windows Security Assessment.
- Linux Security Assessment.
- Server Hardening Validation.
- Patch Verification.
- Configuration Review.
- SSL/TLS Assessment.
- DNS Security.
- SMTP Security.
- Email Security Review.
- Database Security Assessment.
- AWS Security Review.
- Azure Security Review.
- GCP Security Review.
- IAM Review.
- Security Groups.
- Storage Security.
- Cloud Configuration Assessment.
- CIS Benchmark Validation.
- WPA/WPA2/WPA3 Testing.
- Rogue Access Point Detection.
- Wireless Encryption Validation.
- Wireless Authentication Testing.
- Authenticated Scanning.
- Unauthenticated Scanning.
- Vulnerability Verification.
- False Positive Analysis.
- Risk Rating using CVSS v3.1.
- Remediation Recommendations.
- Revalidation Testing.
Knowledge of
- OWASP Top 10
- OWASP API Top 10
- OWASP Mobile Top 10
- OWASP WSTG
- NIST SP 800-115
- PTES
- CVSS v3.1
- CWE
- MITRE ATTCK
- CIS Benchmarks
- SANS Top 25
- PCI DSS
- ISO 27001
- CERT-In Guidelines
- Nessus
- Qualys
- Rapid7 InsightVM
- OpenVAS
- Nexpose
- Burp Suite Professional
- OWASP ZAP
- Acunetix
- Netsparker
- Nmap
- Netcat
- Wireshark
- Metasploit
- Hydra
- Nikto
- MobSF
- Frida
- JADX
- APKTool
- Drozer
- Postman
- Burp Suite
- Swagger
- SoapUI
- ScoutSuite
- Prowler
- AWS Inspector
- Azure Defender
- Prepare detailed VAPT Reports.
- Executive Summary.
- Technical Findings.
- Proof of Concept (PoC).
- Risk Rating.
- CVSS Scoring.
- Impact Analysis.
- Remediation Recommendations.
- Revalidation Reports.
- Closure Reports.
- Analytical Thinking.
- Strong Communication Skills.
- Report Writing.
- Customer Interaction.
- Presentation Skills.
- Time Management.
- Team Collaboration.
- Problem Solving.
- B.E./B.Tech/MCA/B.Sc. in Computer Science, Information Technology, Cyber Security, or equivalent.
- CEH (Certified Ethical Hacker)
- eJPT
- PNPT
- CompTIA Security+
- OSCP (Preferred)
- CRTP (Preferred)
- eCPPT
- ISO 27001 Lead Implementer/Auditor (Optional)
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
