VAPT - Tech Ops Engineer

Niva Bupa
Posted on
Niva Bupa logo

Experience
3 - 5 yrs
Salary (CTC)
₹12L - ₹16L
Job Location
Noida, India
Vacancy
1
Designation
Vapt Engineer
Job Type
Not specified

Job Description

Role & responsibilities

  • VAPT Triaging & Validation: Review, validate, and deduplicate vulnerability findings from internal/external penetration tests, and automated scanners.
  • Risk Contextualization: Perform root-cause analysis on vulnerabilities to determine their actual risk business context (exploitability, impact, and reachability), eliminating false positives before they reach engineering queues.
  • The TechOps Liaison: Act as the primary technical interface between Information Security, Infrastructure (Cloud/SysOps), and Application Dev teams. Translate complex exploit PoCs (Proof of Concepts) into clear, step-by-step remediation tickets (like Jira).
  • Remediation Assistance & Advisory: Don't just point out flawshelp fix them. Provide hand-on technical guidance to Application teams on securing code, and to Infrastructure teams on patching, hardening OS images, updating dependencies, and adjusting network/cloud configurations.
  • SLA & Lifecycle Management: Track the remediation lifecycle from discovery to closure. Ensure all technical teams are adhering to agreed-upon security SLAs (Service Level Agreements) based on vulnerability severity.
  • Re-testing & Verification: Perform technical verification and regression testing to confirm that implemented fixes successfully remediate the vulnerability without impacting system uptime or performance.
  • Metrics & Reporting: Maintain up-to-date vulnerability dashboards. Provide technical metrics to management regarding patch velocity, recurring risk trends, and systemic bottlenecks between teams.

Preferred candidate profile

Technical

  • Strong experience with server hardening, patch management and security baseline Experience: 3-5+ years of experience in a highly collaborative technical role, such as Application Security, VAPT, DevSecOps, Systems Engineering, or Technical Operations.
  • Triaging Expertise: Strong understanding of vulnerability classification frameworks.
  • Systems & Application Fluency: Ability to read and understand code (e.g., Python, Java, JavaScript, or Go) and navigate infrastructure setups (Linux/Windows administration, basic networking, Docker containers, and cloud concepts).
  • Penetration Testing Tools: Familiarity with the tools used to find and validate flaws, such as Burp Suite, Nessus, Qualys, Nmap, or Metasploit.
  • Cross-Team Collaboration: Exceptional communication skills. You must be able to speak "Security" to auditors, "Code" to developers, and "Infrastructure" to system administrators.
  • Ticketing & Workflow Automation: Advanced experience with Jira, ServiceNow, or Azure DevOps, specifically around setting up security workflows, tracking metrics, and technical documentation.

Nice to have

  • Certifications such as CEH (Certified Ethical Hacker), Security+, CompTIA Linux+, or AWS/Azure Fundamentals.
  • Experience working in an Agile/Scrum engineering environment.
  • Knowledge of CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) and how security tooling integrates into TechOps

Behavioral

  • Ownership and Accountability Takes full responsibility for VAPT triaging
  • Collaboration and Influence – Works effective across internal teams and external vendors.
  • Communication – Communicates technical issues clearly to both technical and non-technical audience
  • Analytical Thinking – Uses structured thinking and data-driven approach to solve problems, assess risks and make recommendations

Adaptability – Thrives in dynamic environment.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.