TymblHub

© 2026 TymblHub

VAPT Engineer

iValue Group
Posted on
iValue Group logo

Experience
2 - 6 yrs
Job Location
Bengaluru, India
Vacancy
1
Designation
Vapt Engineer
Job Type
ONSITE

Job Description

Job Summary
We are seeking a skilled VAPT Engineer responsible for performing comprehensive Vulnerability Assessment and Penetration Testing across web applications, mobile applications, APIs, network infrastructure, cloud environments, wireless networks, and thick client applications. The candidate should possess strong knowledge of cybersecurity principles, vulnerability identification, exploitation techniques, remediation validation, and report preparation while adhering to industry standards and best practices.
Key Responsibilities Web Application Security Testing
  • Perform Web Application VAPT using OWASP WSTG methodology.
  • Identify OWASP Top 10 vulnerabilities.
  • Manual vulnerability verification.
  • Authentication Authorization Testing.
  • Session Management Testing.
  • Business Logic Testing.
  • Input Validation Testing.
  • File Upload Security Testing.
  • API Security Testing.
  • Source Code Review (basic understanding).
Mobile Application Security
  • Android Security Assessment.
  • iOS Security Assessment.
  • OWASP Mobile Top 10 Testing.
  • Reverse Engineering Basics.
  • Certificate Pinning Validation.
  • Local Storage Assessment.
  • Secure Communication Testing.
API Security Assessment
  • REST API Security Testing.
  • SOAP API Testing.
  • GraphQL Security Assessment.
  • JWT Token Testing.
  • OAuth Authentication Testing.
  • Rate Limiting Validation.
  • Authorization Testing.
  • Business Logic Testing.
Network VAPT
  • External Network Assessment.
  • Internal Network Assessment.
  • Firewall Security Review.
  • Switch Security Assessment.
  • Router Security Assessment.
  • VPN Security Testing.
  • Wireless Security Assessment.
  • Active Directory Assessment.
  • Windows Security Assessment.
  • Linux Security Assessment.
Infrastructure Security
  • Server Hardening Validation.
  • Patch Verification.
  • Configuration Review.
  • SSL/TLS Assessment.
  • DNS Security.
  • SMTP Security.
  • Email Security Review.
  • Database Security Assessment.
Cloud Security Assessment
  • AWS Security Review.
  • Azure Security Review.
  • GCP Security Review.
  • IAM Review.
  • Security Groups.
  • Storage Security.
  • Cloud Configuration Assessment.
  • CIS Benchmark Validation.
Wireless Security
  • WPA/WPA2/WPA3 Testing.
  • Rogue Access Point Detection.
  • Wireless Encryption Validation.
  • Wireless Authentication Testing.
Vulnerability Assessment
  • Authenticated Scanning.
  • Unauthenticated Scanning.
  • Vulnerability Verification.
  • False Positive Analysis.
  • Risk Rating using CVSS v3.1.
  • Remediation Recommendations.
  • Revalidation Testing.
Security Standards
Knowledge of

  • OWASP Top 10
  • OWASP API Top 10
  • OWASP Mobile Top 10
  • OWASP WSTG
  • NIST SP 800-115
  • PTES
  • CVSS v3.1
  • CWE
  • MITRE ATTCK
  • CIS Benchmarks
  • SANS Top 25
  • PCI DSS
  • ISO 27001
  • CERT-In Guidelines
Security Tools Vulnerability Scanners
  • Nessus
  • Qualys
  • Rapid7 InsightVM
  • OpenVAS
  • Nexpose
Web Security
  • Burp Suite Professional
  • OWASP ZAP
  • Acunetix
  • Netsparker
Network Tools
  • Nmap
  • Netcat
  • Wireshark
  • Metasploit
  • Hydra
  • Nikto
Mobile Testing
  • MobSF
  • Frida
  • JADX
  • APKTool
  • Drozer
API Testing
  • Postman
  • Burp Suite
  • Swagger
  • SoapUI
Cloud Tools
  • ScoutSuite
  • Prowler
  • AWS Inspector
  • Azure Defender
Reporting Responsibilities
  • Prepare detailed VAPT Reports.
  • Executive Summary.
  • Technical Findings.
  • Proof of Concept (PoC).
  • Risk Rating.
  • CVSS Scoring.
  • Impact Analysis.
  • Remediation Recommendations.
  • Revalidation Reports.
  • Closure Reports.
Soft Skills
  • Analytical Thinking.
  • Strong Communication Skills.
  • Report Writing.
  • Customer Interaction.
  • Presentation Skills.
  • Time Management.
  • Team Collaboration.
  • Problem Solving.
Educational Qualification
  • B.E./B.Tech/MCA/B.Sc. in Computer Science, Information Technology, Cyber Security, or equivalent.
Preferred Certifications
  • CEH (Certified Ethical Hacker)
  • eJPT
  • PNPT
  • CompTIA Security+
  • OSCP (Preferred)
  • CRTP (Preferred)
  • eCPPT
  • ISO 27001 Lead Implementer/Auditor (Optional)

Disclaimer: This job posting & Location has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.