Lead VAPT

16 hours ago


DoubleTree by Hilton Hotel Gurgaon New Delhi NCR, India Airtel Full time

Job Title: Lead Offensive Security and Vulnerability Management

Location: Gurugram

Job Type: Full-Time

Role Overview: We are seeking a highly skilled Lead VAPT to lead offensive security and vulnerability management across Airtel's telecom ecosystem, spanning 2G, 4G, 5G SA/NSA, Fixed Wireless Access (Consumer & Enterprise Services), Wi-Fi, Homes & Broadband, NLD/ILD, DTH, Enterprise, and Transport.

This role will oversee telecom protocol penetration testing, attack surface management, red teaming, and vulnerability assessments, while also leading the vulnerability management lifecycle (VM) end-to-end — from discovery and risk rating to closure governance with managed service partners (MSS), OEMs, and domain owners.

This role works independently, owning the Offensive Security and Vulnerability Management vertical end-to-end, while leading MSS teams for delivery and collaborating with other Leads as part of a unified security leadership team.

Key Responsibilities:

Strategic Impact

  • Define and execute Airtel's VAPT and vulnerability management strategy aligned with business and regulatory objectives.
  • Build an attack surface management program covering telecom networks, enterprise IT, and customer-facing platforms.
  • Enhance offensive security practices with protocol-level testing and red team simulations.

Operational Excellence

  • Lead periodic vulnerability scans Airtel's telecom ecosystem, spanning 2G, 4G, 5G SA/NSA, Fixed Wireless Access (Consumer & Enterprise Services), Wi-Fi, Homes & Broadband, NLD/ILD, DTH, Enterprise, and Transport
  • Conduct telecom protocol penetration testing eg. SS7, Diameter, SIP, and GTP.
  • Manage new node VA scans before deployment to production.
  • Perform application security assessments for Airtel's consumer/enterprise apps and APIs.
  • Conduct cloud-native security testing for 5G core CNFs/VNFs and enterprise workloads.
  • Develop custom scripts and tools to automate protocol fuzzing, exploit validation, and attack simulations
  • Oversee red team exercises and adversary simulations to validate SOC detection and IR readiness.
  • Lead the end-to-end vulnerability lifecycle: identification, prioritization, remediation tracking, exception management, and closure.
  • Deliver risk-based reports with actionable remediation guidance for technical teams and leadership.

Leadership & Collaboration

  • Lead and manage the MSS Vulnerability Assessment team and ensure timely deliverables.
  • Govern risk closure with domain owners, OEMs, and managed service partners through structured governance.
  • Work with SOC, Build, and GRC teams to ensure detection coverage, policy compliance, and risk governance.
  • Engage in executive-level governance reporting on vulnerability posture, remediation SLAs, and red team outcomes.
  • Work as the single point of accountability for VM lifecycle management.

Required Skills and Experience:

  • 8+ years of experience in VAPT, offensive security, and vulnerability management leadership.
  • Strong expertise in telecom network protocol testing
  • Hands-on with VA/PT tools (eg. Tenable SC, Nessus, Nexpose, Burp Suite, Metasploit, custom telecom fuzzers, Wireshark).
  • Experience in vulnerability lifecycle governance (tracking, closure, exception handling, SLA reporting).
  • Knowledge of attack surface management, red teaming, adversary simulations, and hands-on.
  • Strong understanding of network stack – Mobility, Transport, Broadband, Enterprise, Wi-Fi, Homes, DTH.
  • Proven ability to work with OEMs, MSSPs, and internal domain owners for coordinated remediation.

Preferred Qualifications:

  • Certifications: OSCP, OSWE, GPEN, GXPN, CEH (Practical), CISA/CISM for risk governance.
  • Experience in telecom security testing or managed security service delivery.
  • Familiarity with 3GPP, GSMA FS.11, ISO 27011, and NESAS/SCAS frameworks.
  • Exposure to cloud-native 5G security testing (CNFs, VNFs, API security).

Why Join Us?

  • Lead the entire VAPT and vulnerability management function for one of the leading telecommunications companies globally.
  • Drive both offensive security (protocol/PT, red team) and defensive risk closure governance.
  • Collaborate with OEMs, MSSPs, and regulators to strengthen Airtel's cyber resilience.

  • Lead VAPT

    2 days ago


    Delhi, Gurugram, NCR, India Airtel Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job Title: Lead Offensive Security and Vulnerability ManagementLocation: GurugramJob Type: Full-TimeRole Overview: We are seeking a highly skilled Lead VAPT to lead offensive security and vulnerability management across Airtel's telecom ecosystem, spanning 2G, 4G, 5G SA/NSA, Fixed Wireless Access (Consumer & Enterprise Services), Wi-Fi, Homes & Broadband,...

  • VAPT Manager

    2 weeks ago


    Gurgaon, Haryana, India Cubical Operations LLP Full time ₹ 15,00,000 - ₹ 20,00,000 per year

    Job Title:VAPT Manager / Sr. ManagerLocation:Mumbai / GurgaonExperience:Minimum 6 yearsJob Type:Full-timeDepartment:Cybersecurity / Information SecurityAbout the Role:We are seeking a highly skilled and experiencedVulnerability Assessment and Penetration Testing (VAPT) Manager / Sr. Managerto join our growing cybersecurity team. The ideal candidate will lead...


  • Gurgaon, Haryana, India Cubical Operations LLP Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Job Description – VAPT Associate Director (Mumbai)Position: Associate Director – Vulnerability Assessment & Penetration Testing (VAPT)Location: MumbaiExperience: 8+ YearsDepartment: Cybersecurity / Risk AdvisoryEmployment Type: Full-TimeAbout the RoleWe are seeking an experiencedVAPT Associate Directorto lead our cybersecurity testing engagements, manage...

  • VAPT OSCP

    4 days ago


    Delhi, India Cubical Operations LLP Full time

    Job Description: VAPT (OSCP) Manager / Senior ManagerLocation:Remote (India) | Frequent Travel to the Middle EastExperience:6+ YearsPosition Level:Manager / Senior ManagerEmployment Type:Full-TimeAbout the RoleWe are seeking an experiencedVulnerability Assessment & Penetration Testing (VAPT)professional with a strong background in offensive security...


  • Delhi, NCR, gurgoan, India MC Placement Services Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Role & responsibilitiesLead enterprise web and mobile application development.Manage application lifecycle and ensure VAPT compliance.Collaborate with ERP, CRM, HRMS, and Logistics teams.Drive SAP/Oracle integrations and ETL automation initiatives.Support Power BI reporting and digital transformation projects.Mentor and manage developer teams (backend,...


  • Delhi, NCR, India Dataconfiance Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    DataConfiance seeks experienced Cyber Security Consultant (CISSP, 6+ yrs). Lead assessments, design security frameworks, and guide teams across industries. Learn More: Required Candidate profileCISSP required, 6+ yrs cybersecurity. Acumen in ISO 27001, NIST, PCI DSS, SOC2, SIEM, IAM, cloud security, VAPT, SAST/DAST tools. Skilled in app security, threat...


  • NCR, India Dataconfiance Full time

    DataConfiance seeks experienced Cyber Security Consultant (CISSP, 6+ yrs). Lead assessments, design security frameworks, and guide teams across industries. Learn More: Required Candidate profile CISSP required, 6+ yrs cybersecurity. Acumen in ISO 27001, NIST, PCI DSS, SOC2, SIEM, IAM, cloud security, VAPT, SAST/DAST tools. Skilled in app security, threat...


  • Delhi, Delhi, India beBeePenetration Full time ₹ 12,00,000 - ₹ 36,00,000

    Job Description:We are seeking a skilled Vulnerability Assessment and Penetration Testing (VAPT) Consultant to join our team.The successful candidate will be responsible for planning, coordinating, and executing VAPT activities to identify and remediate security vulnerabilities in Bank applications.This role requires a comprehensive understanding of OWASP...

  • Cyber risk

    1 week ago


    Gurgaon, Haryana, India KPMG Assurance and Consulting Services LLP Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    >>Technical SkillsExpertise in cyber security including standards such as ISO27001, PCI-DSS, ISO22301, Privacy etc.Knowledge of technical domains such as Cloud security, VAPT, Application security, Risk and control assessment, Technology risk assessments, IT or OT compliance, Data privacy, and Network securityKnowledge of concepts such as Shadow IT, Vendor...

  • Lead AI

    2 weeks ago


    Delhi, NCR, New Delhi, Okhla Industrial Est, India Career Management Services Full time US$ 1,50,000 - US$ 2,00,000 per year

    Preferred Candidate: General Corporate Lawyer with understanding of all practice areas workflows, keen interest in technology and AI. Working in Legal Tech companies or legal tech roles in top law-firmsPosition Summary:The Lead AI & Law-Tech will drive the firms vision to be the most digitally advanced legal firm, overseeing enterprise-wide strategy,...