Lead VAPT

3 weeks ago


DoubleTree by Hilton Hotel Gurgaon New Delhi NCR, India Airtel Full time

Job Title: Lead Offensive Security and Vulnerability Management

Location: Gurugram

Job Type: Full-Time

Role Overview: We are seeking a highly skilled Lead VAPT to lead offensive security and vulnerability management across Airtel's telecom ecosystem, spanning 2G, 4G, 5G SA/NSA, Fixed Wireless Access (Consumer & Enterprise Services), Wi-Fi, Homes & Broadband, NLD/ILD, DTH, Enterprise, and Transport.

This role will oversee telecom protocol penetration testing, attack surface management, red teaming, and vulnerability assessments, while also leading the vulnerability management lifecycle (VM) end-to-end — from discovery and risk rating to closure governance with managed service partners (MSS), OEMs, and domain owners.

This role works independently, owning the Offensive Security and Vulnerability Management vertical end-to-end, while leading MSS teams for delivery and collaborating with other Leads as part of a unified security leadership team.

Key Responsibilities:

Strategic Impact

  • Define and execute Airtel's VAPT and vulnerability management strategy aligned with business and regulatory objectives.
  • Build an attack surface management program covering telecom networks, enterprise IT, and customer-facing platforms.
  • Enhance offensive security practices with protocol-level testing and red team simulations.

Operational Excellence

  • Lead periodic vulnerability scans Airtel's telecom ecosystem, spanning 2G, 4G, 5G SA/NSA, Fixed Wireless Access (Consumer & Enterprise Services), Wi-Fi, Homes & Broadband, NLD/ILD, DTH, Enterprise, and Transport
  • Conduct telecom protocol penetration testing eg. SS7, Diameter, SIP, and GTP.
  • Manage new node VA scans before deployment to production.
  • Perform application security assessments for Airtel's consumer/enterprise apps and APIs.
  • Conduct cloud-native security testing for 5G core CNFs/VNFs and enterprise workloads.
  • Develop custom scripts and tools to automate protocol fuzzing, exploit validation, and attack simulations
  • Oversee red team exercises and adversary simulations to validate SOC detection and IR readiness.
  • Lead the end-to-end vulnerability lifecycle: identification, prioritization, remediation tracking, exception management, and closure.
  • Deliver risk-based reports with actionable remediation guidance for technical teams and leadership.

Leadership & Collaboration

  • Lead and manage the MSS Vulnerability Assessment team and ensure timely deliverables.
  • Govern risk closure with domain owners, OEMs, and managed service partners through structured governance.
  • Work with SOC, Build, and GRC teams to ensure detection coverage, policy compliance, and risk governance.
  • Engage in executive-level governance reporting on vulnerability posture, remediation SLAs, and red team outcomes.
  • Work as the single point of accountability for VM lifecycle management.

Required Skills and Experience:

  • 8+ years of experience in VAPT, offensive security, and vulnerability management leadership.
  • Strong expertise in telecom network protocol testing
  • Hands-on with VA/PT tools (eg. Tenable SC, Nessus, Nexpose, Burp Suite, Metasploit, custom telecom fuzzers, Wireshark).
  • Experience in vulnerability lifecycle governance (tracking, closure, exception handling, SLA reporting).
  • Knowledge of attack surface management, red teaming, adversary simulations, and hands-on.
  • Strong understanding of network stack – Mobility, Transport, Broadband, Enterprise, Wi-Fi, Homes, DTH.
  • Proven ability to work with OEMs, MSSPs, and internal domain owners for coordinated remediation.

Preferred Qualifications:

  • Certifications: OSCP, OSWE, GPEN, GXPN, CEH (Practical), CISA/CISM for risk governance.
  • Experience in telecom security testing or managed security service delivery.
  • Familiarity with 3GPP, GSMA FS.11, ISO 27011, and NESAS/SCAS frameworks.
  • Exposure to cloud-native 5G security testing (CNFs, VNFs, API security).

Why Join Us?

  • Lead the entire VAPT and vulnerability management function for one of the leading telecommunications companies globally.
  • Drive both offensive security (protocol/PT, red team) and defensive risk closure governance.
  • Collaborate with OEMs, MSSPs, and regulators to strengthen Airtel's cyber resilience.

  • Lead VAPT

    2 days ago


    Delhi, Gurugram, NCR, India Airtel Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job Title: Lead Offensive Security and Vulnerability ManagementLocation: GurugramJob Type: Full-TimeRole Overview: We are seeking a highly skilled Lead VAPT to lead offensive security and vulnerability management across Airtel's telecom ecosystem, spanning 2G, 4G, 5G SA/NSA, Fixed Wireless Access (Consumer & Enterprise Services), Wi-Fi, Homes & Broadband,...

  • VAPT Manager

    2 weeks ago


    Gurgaon, Haryana, India Cubical Operations LLP Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Job Title:VAPT Manager / Sr. ManagerLocation:Mumbai / GurgaonExperience:Minimum 6 yearsJob Type:Full-timeDepartment:Cybersecurity / Information SecurityAbout the Role:We are seeking a highly skilled and experiencedVulnerability Assessment and Penetration Testing (VAPT) Manager / Sr. Managerto join our growing cybersecurity team. The ideal candidate will lead...


  • Gurgaon, Haryana, India Cubical Operations LLP Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Job Description – VAPT Associate Director (Mumbai)Position: Associate Director – Vulnerability Assessment & Penetration Testing (VAPT)Location: MumbaiExperience: 8+ YearsDepartment: Cybersecurity / Risk AdvisoryEmployment Type: Full-TimeAbout the RoleWe are seeking an experiencedVAPT Associate Directorto lead our cybersecurity testing engagements, manage...

  • VAPT Engineer

    6 days ago


    Gurgaon, Haryana, India ACPL Systems Full time ₹ 4,00,000 - ₹ 8,00,000 per year

    About ACPL )We at ACPL are Cyber Security specialists and help corporates with their complete cycle of setting up the Cyber security platform. Right from selecting the adaptable security tools to the deployment of the same and then providing dedicated cybersecurity services.Established in 1990, ACPL is the developer of India's first antivirus software...

  • Lead Generation

    1 week ago


    New Delhi, India va2pt.com Full time

    We are the catalyst for your DevOps and Cyber Security team. We provide #DevOps, #DevSecOps, #SRE, #VAPT, #ISO, #SoC2 Services. The Role Job Title: Lead Generation Executive Company: VA2PT Location: New Delhi Employment Type: Full-Time Experience: 0-1 year About VA2PT: VA2PT is a trusted partner for DevOps and Cybersecurity teams, offering expert...

  • Lead Generation

    1 week ago


    New Delhi, India va2pt.com Full time

    We are the catalyst for your DevOps and Cyber Security team. We provide #DevOps, #DevSecOps, #SRE, #VAPT, #ISO, #SoC2 Services. The Role Job Title: Lead Generation Executive Company: VA2PT Location: New Delhi Employment Type: Full-Time Experience: 0-1 year About VA2PT: VA2PT is a trusted partner for DevOps and Cybersecurity teams, offering expert services...

  • Technical Manager

    3 days ago


    New Delhi, India Eventus Security Full time

    Eventus Securityprovides reliable and customized security solutions. With a trained team and a client-first approach, we ensure safety, trust, and peace of mind across corporate, residential, and industrial sectors.Job Title: Technical Manager - Cyber Resilience Experience: 8yrs+ Job Location: Navi MumbaiJob Role: Eventus Security requires a Technical...


  • Delhi, NCR, gurgoan, India MC Placement Services Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Role & responsibilitiesLead enterprise web and mobile application development.Manage application lifecycle and ensure VAPT compliance.Collaborate with ERP, CRM, HRMS, and Logistics teams.Drive SAP/Oracle integrations and ETL automation initiatives.Support Power BI reporting and digital transformation projects.Mentor and manage developer teams (backend,...


  • New Delhi, India Deloitte Full time

    Your potential, unleashed. India’s impact on the global economy has increased at an exponential rate and Deloitte presents an opportunity to unleash and realize your potential amongst cutting edge leaders, and organizations shaping the future of the region, and indeed, the world beyond.At Deloitte, your whole self to work, every day. Combine that with our...


  • Gurgaon, Haryana, India Delhivery Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Experience & Skills5+ years of progressive experience in cybersecurity roles, with a proven track record in managing complex security initiatives.Minimum of 1-2 years of proven team handling or technical leadership experience mentoring engineers, defining project tasks, and managing team workload.Expert-level, hands-on experience managing and executing VAPT...