Vapt Engineer

KPMG Assurance and Consulting Services LLP
Posted on
KPMG Assurance and Consulting Services LLP logo

Experience
2 - 5 yrs
Salary (CTC)
₹2L - ₹5.5L
Job Location
Noida, India
Vacancy
1
Designation
Vapt Engineer
Job Type
Not specified

Job Description

Dear,

we are hiring for VAPT enigneer

Experience: 3+ years with at-least 2-3 years in client facing advisory consulting role and managing a medium sized team


Preferred Certifications: CEH, ECSA, OSCP, CISSP, CCSK, OCSE, CCSP, AWS Security


  • Desired skill set:

1. Strong understanding of IT security standards and frameworks (OWASP, NIST, CIS)

2. Strong understanding of security risks in networks and application platforms

3. Strong understanding of network security, infrastructure security and application security

4. Strong understanding of OSI, TCP/IP model and network basics

5. Demonstrate technical penetration testing skills on IT infrastructure, web applications, mobile platforms and Red teaming

6. Strong technical skills: Information security, network security, Windows security, UNIX/Linux security, web and mobile application security, Cloud platforms

7. Broad knowledge of security technologies for applications, databases, networks, servers, and desktops

8. Solid technical skills in both information security architecture and penetration testing and ability to assess testing tools and deploy the right ones.

9. Scripting and programming experience is beneficial

10. Ability to perform manual penetration testing

11. Experience in Application Security Testing (Web, Mobile & ERP [SAP]), or related functions Vulnerability Assessment, Penetration testing

12. Perform penetration testing of various thick client software, web applications, and communications infrastructure to assist in hardening the cybersecurity posture against malicious actors

13. Conduct security research on the latest emerging advanced persistent threats (APTs), malware, and other security developments to assist in enterprise security efforts. Apply this security research into assessments.

14. Perform technical writing to communicate the preparation, testing, and recommendation phases for various security tests. Work with stakeholders to remediate system vulnerabilities.

15. Train team members and colleagues on the latest cybersecurity tactics, techniques, and procedures (TTPs) to grow the skill of the firm

16. Understanding of various security technologies including end point security, perimeter security, advanced threat protection, malware defense and security management

17. Expertise in the phases of penetration testing. Familiarity with Kali Linux distribution and the associated penetration testing tools suite. Experience in penetration testing simulations like Hack the Box or Capture the Flag exercises considered a plus.

18. Good Understanding of OWASP top 10 and mitigation techniques

19. Experience in performing web application security assessments using hands on techniques for identifying SQL injections, XSS, Security Misconfiguration, CSRF, authentication/ authorization issues

20. Database testing: MySQL, Oracle, NoSQL

21. Understanding of cyber security management, cyber analytics, security intelligence platforms and threat intelligence frameworks

22. Writing business proposals and response to client RFP/ RFIs

23. Identifying business opportunities and lead delivery and program management for large cyber security programs

24. Delivery team and client relationship management

25. Experience on both commercial, open source tools and frameworks but not limited: Burpsuite, Metasploit, Core-Impact, Kali-Linux, AppScan, WebInspect, SSLScan, Soap UI Pro, SonarQube, Qualys, Nikto, Nessus, nmap, sqlmap, OWASP ZAP .


Interested candidates can share resume with below details

current ctc

exp ctc

notice period

current location

any certifications

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.