Job Description
About Position:
We are looking for a skilled VAPT Engineer / Application Security Engineer / Security Analyst to identify, assess, and help remediate security vulnerabilities across applications, APIs, networks, and enterprise infrastructure. The ideal candidate will have hands-on experience in vulnerability assessment, penetration testing, secure SDLC practices, and application security while working closely with development, DevOps, and product teams to improve the organization's overall security posture
- Role: VAPT Engineer
- Location: Pune
- Experience: 5 to 8 years
- Job Type: Full-Time Employment
What You'll Do:
- Perform Vulnerability Assessments and Penetration Testing (VAPT) on web applications, APIs, networks, and infrastructure.
- Conduct manual security testing covering OWASP Top 10, SANS Top 25, and business logic vulnerabilities.
- Utilize automated security testing tools and validate findings to eliminate false positives.
- Prepare detailed VAPT reports with risk ratings, attack scenarios, proof of concepts, and remediation recommendations.
- Re-test vulnerabilities after remediation to validate closure.
- Collaborate with developers, DevOps, and product teams during vulnerability triage and remediation activities.
- Support Secure SDLC initiatives including design reviews, threat modeling, and security sign-offs for releases.
- Participate in security assessments and compliance activities related to ISO 27001, SOC2, PCI-DSS, and other standards.
- Contribute to improving application, API, and infrastructure security across the organization.
Expertise You'll Bring:
- 3 to 5 years of handson experience in Vulnerability Assessment and Penetration Testing (VAPT), Application Security, or Cybersecurity.
- Strong understanding of OWASP Top 10, SANS Top 25, Web Security, API Security, and AI Security concepts.
- Hands-on experience with security testing tools such as Burp Suite, OWASP ZAP, Nessus, Qualys, OpenVAS, Nmap, and Metasploit.
- Experience performing web application, API, network, and infrastructure security assessments.
- Strong understanding of vulnerability management, risk assessment, and remediation processes.
- Ability to identify, validate, and exploit security vulnerabilities using manual and automated testing techniques.
- Experience creating detailed security assessment reports and remediation guidance.
- Ability to read and understand source code in at least one programming language such as Java, Python, JavaScript, or C#.
- Experience supporting Secure SDLC activities including threat modeling, design reviews, and release security assessments.
- Experience working in Agile, DevSecOps, or security-focused development environments.
- Knowledge of security compliance standards such as ISO 27001, SOC2, and PCI-DSS.
- Strong analytical, troubleshooting, and problem-solving skills.
- Excellent communication and stakeholder management capabilities.
- CEH (Certified Ethical Hacker) certification.
- OSCP or OSWE certification.
- Knowledge of cloud security across AWS, Azure, and GCP.
- Experience with CI/CD security practices and DevSecOps implementations.
- Exposure to SAST, DAST, and application security testing tools.
- Familiarity with secure coding practices and security architecture concepts.
- Scripting and automation experience using Python, Bash, or PowerShell.
- Experience securing modern cloud-native and microservices-based applications.
Benefits:
- Competitive salary and benefits package
- Culture focused on talent development with quarterly growth opportunities and company-sponsored higher education and certifications
- Opportunity to work with cutting-edge technologies
- Employee engagement initiatives such as project parties, flexible work hours, and Long Service awards
- Annual health check-ups
- Insurance coverage: group term life, personal accident, and Mediclaim hospitalization for self, spouse, two children, and parents
Values-Driven, People-Centric & Inclusive Work Environment:
Persistent is dedicated to fostering diversity and inclusion in the workplace. We invite applications from all qualified individuals, including those with disabilities, and regardless of gender or gender preference. We welcome diverse candidates from all backgrounds.
- We support hybrid work and flexible hours to fit diverse lifestyles.
- Our office is accessibility-friendly, with ergonomic setups and assistive technologies to support employees with physical disabilities.
- If you are a person with disabilities and have specific requirements, please inform us during the application process or at any time during your employment
Let's unleash your full potential at Persistent - persistent.com/careers
"Persistent is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind."
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
