Requirements
The candidate will be responsible for conducting comprehensive Vulnerability Assessment and Penetration Testing (VAPT) across enterprise IT environments, applications, networks, infrastructure, cloud platforms and security systems. Key responsibilities include internal and external penetration testing, web application and API penetration testing, vulnerability assessments, controlled exploitation, security testing of network devices and applications, source-code security reviews, cloud environment security assessments, and utilizing tools like Burp Suite, Nmap, Nessus, Metasploit, Wireshark, and Kali Linux. Proficiency in Python for security automation is required. Knowledge of cybersecurity standards and methodologies such as OWASP, NIST, ISO/IEC 27001, and PCI DSS is also necessary.
Description
The candidate will be responsible for conducting comprehensive Vulnerability Assessment and Penetration Testing (VAPT) across enterprise IT environments, applications, networks, infrastructure, cloud platforms and security systems.Key ResponsibilitiesConduct internal and external penetration testing across networks, servers, firewalls, endpoints and infrastructure.Perform web application and API penetration testing, including testing against OWASP vulnerabilities.Conduct vulnerability assessments and manually validate identified vulnerabilities and false positives.Perform controlled exploitation to determine the actual impact and severity of identified security weaknesses.Conduct security testing of network devices, firewalls, routers, switches, VPNs, load balancers and servers.Perform application security testing covering authentication, authorization, session management, input validation, encryption and business-logic vulnerabilities.Conduct source-code security reviews and support SAST/DAST activities.Assess security of cloud environments and operating systems.Perform security assessments using tools such as Burp Suite, Nmap, Nessus, Metasploit, Wireshark and Kali Linux.Develop or automate penetration-testing/security activities using Python.Prepare detailed penetration-testing and vulnerability-assessment reports containing evidence, risk ratings, business impact and remediation recommendations.Work with technical teams to remediate identified vulnerabilities.Conduct retesting and validation after remediation.Follow established penetration-testing methodologies and cybersecurity best practices.Support security teams in identifying attack vectors and improving the organization's overall security posture.Required Technical SkillsStrong hands-on knowledge of:Vulnerability Assessment & Penetration Testing (VAPT)Network Penetration TestingWeb Application Penetration TestingAPI Security TestingInfrastructure Security TestingCloud Security TestingVulnerability Exploitation & ValidationOWASP Top 10SAST & DASTSource-Code Security AnalysisSecure Coding PracticesNetwork & Operating System SecurityPython/Security AutomationBurp SuiteNmapNessusMetasploitWiresharkKali LinuxRequirementsStandards / Framework KnowledgeThe candidate should have good knowledge of relevant cybersecurity standards and methodologies, including:OWASPNISTISO/IEC 27001PCI DSSPenetration-testing methodologies and security best practices