
Hiring Client•12d ago
Naukri
VAPT Consultant
Bengaluru
Full Time
Mid Level
N/A
N/A
N/A
Qualifications & Requirements
Experience Level: Mid Level
Full Job Description
About the Role
We are seeking a highly skilled VAPT Consultant with a keen ability for identifying real-time vulnerabilities through rigorous manual analysis, rather than relying solely on automated tools. This role requires a proactive security professional who can assess and strengthen our clients' security posture across various digital environments.
Key Responsibilities
- Conduct comprehensive Vulnerability Assessment and Penetration Testing (VAPT) for web applications (including thin and thick clients), mobile applications, APIs, and network infrastructures.
- Perform both manual and automated security assessments, utilizing Black Box and White Box testing methodologies.
- Execute in-depth network penetration tests, system vulnerability assessments, and detailed security configuration reviews.
- Analyze source code manually and with automated tools to identify critical business logic vulnerabilities.
- Engage in Red Team activities, simulating real-world cyber-attack scenarios to test defenses.
- Review and validate configurations for operating systems (Windows, Linux), databases, firewalls, routers, switches, and other security devices.
- Develop and present detailed technical reports, including executive summaries, for clients.
- Provide clients with timely status updates on ongoing assessments and offer practical remediation guidance.
- Continuously monitor emerging threats, exploits, and vulnerabilities, contributing to threat intelligence inputs.
About You
Required Skills
- Solid understanding of OWASP Top 10, OWASP Testing Guide, and SANS security standards.
- Proficient hands-on experience with VAPT tools such as Burp Suite, Nessus, Metasploit, Kali Linux, Netsparker, Nexpose, AppScan, and Acunetix.
- Demonstrated experience in web application security, API security, and network penetration testing.
- Knowledge of secure coding practices and CIS Security Benchmarks.
- Experience working within Windows and Linux environments.
- Capability to modify or compile exploit code is a significant advantage.
- Excellent report writing and client communication skills.
- Proficiency in Microsoft Office Suite (Word, Excel, PowerPoint).
Good to Have
- Scripting skills in Python, Perl, Ruby, or PHP.
- Relevant security certifications such as OSCP, CISSP, or CSSLP.
Company
Hiring Client
Bengaluru
Posted on Naukri