VAPT Engineer

5 days ago


Guwahati India Jio Full time

Job Description Skills: Nessus, Burp Suite, Metasploit, OWASP ZAP, Nmap, Qualys, Wireshark, Kali Linux, Position: VAPT Engineer Reporting to: Platform Lead Infrastructure Security Employment Type: Employee - Full Time Work Location: Guwahati Key Focus area: Infrastructure Penetration Tester Key Responsibilities - Identification and remediation of new vulnerabilities and risk analysis for Infrastructure is a key responsibility. - Identifying and maintaining Key metrics and SLA on Infrastructure Security. - Ensure that vulnerability assessments are performed to evaluate effectiveness of security controls in applications, middleware, databases, network and operating systems. - Thorough experience in configurations reviews against CIS benchmarks and security standards. - Ensure all Hardening and Patching activities are conducted and tracked as per defined policies. - Create/Update hardening documents and build audit file for automated testing. - Knowledge of current and emerging security threats and techniques for exploiting security vulnerabilities. - Conduct security penetration testing to identify vulnerabilities and potential security risks along with designing and implement security solutions to protect enterprise systems, applications, data, assets, and people. - Collaborate with cross-functional teams to ensure security measures are integrated into all aspects of the organization's operations. - Perform Internal/ External Penetration Testing on Jio Infrastructure and producing reports with recommendations for detailed penetration testing findings. - Sound understanding of Azure/GCP/AWS environment activities and Perform Vulnerability Assessment & Penetration Testing for networks (internal & external), applications, APIs & cloud assets along with Red & Purple Team assessments. - Safeguarding information, infrastructures, applications, and business processes against cyber threats. - Proactively create, share, and read reports as part of the penetration testing activities. - Responsible for utilizing threat intelligence to identify new threats in our environment, coordinating with stakeholders to remediate identified vulnerabilities, and ensuring closure through thorough cross-validation. Qualification And Work Experience - Qualification: BE / BTech (Similar Education Background) - Work experience: 7-15 Years - 7+ years of experience in Infrastructure Penetration Testing and Vulnerability Management including practical experience with Linux and Windows operating systems. - Thorough understanding of Application and Infrastructure Architectures, and related vulnerabilities. Ability to interpret and prioritize vulnerability scan results into remediation actions and tracking those actions through to completion. - Working knowledge of ORACLE DB, MS SQL DB, MYSQL DB & Network Devices is required. - Ability to analyse vulnerabilities to appropriately characterize threats and provide remediation advice. Familiarity with classes of vulnerabilities, appropriate remediation, and industry-standard classification schemes (CVE, CVSS, CPE). - Extensive experience in vulnerability management, including the ability to forecast potential threats and develop proactive mitigation plans. - Hands on experience in testing diverse infra components including various enterprise platforms such as private clouds, OpenShift infra, dockers/container infra etc. - The candidate should be able to perform manual & automated penetration testing for internal, external perimeter, web applications, IT infrastructure, end-points, cloud etc. using hacking tools; e.g. Nuclei, Acunetix, BURP, Wireshark, Nmap, netcat, Firebug, Nessus, Kali OS, Parrot, Metasploit, Aircrack-ng. - Preferred: Security related professional certification (e.g. CEH, CPENT, OSCP, OSCE, OSWE, GPEN, GWAPT or similar certifications) - Preferred: Script writing skills (Python/Ruby/bash/PowerShell). - Experience with security standards and frameworks such as ISO 27001, NIST, and PCI DSS. - Preferred: Security solutions technologies such as IPS, firewalls, endpoint protection, web/email filtering, DLP, Digital rights management, encryption, SEIM, and virtualization platforms. - Expertise in performing grey box/Black box testing. - Experience devising methods to automate testing activities and streamline testing processes. - Proven ability to develop and test Proof of Concept (PoC) exploits as part of vulnerability assessment and penetration testing exercises. Competencies / Expertise Required (Functional & Behavioral) - Systematic strong analytical thinking and problem-solving skills. - Excellent in analytical thinking for translating data into informative visuals and reports. - Adaptable to change. - Quick Learner Open learn and work on new technologies and products. If you're interested, please share below mention details for the same. - Location - Preferred location - Current Co - Experience - Current CTC - Expected CTC - Notice Period - Offer in Hand - Highest Education - SSC % - HSC % - Graduation % - University Name Regards, Ashwini Chakor


  • VAPT Engineer

    2 weeks ago


    Guwahati, India Jio Full time

    Position: VAPT Engineer Reporting to: Platform Lead Infrastructure Security Employment Type: Employee - Full Time Work Location: Guwahati Key Focus area: Infrastructure Penetration Tester Key Responsibilities: Identification and remediation of new vulnerabilities and risk analysis for Infrastructure is a key responsibility. Identifying and maintaining...


  • Nagar, Sahibzada Ajit Singh Nagar, India Cybrain Software Solutions Pvt.Ltd Full time

    Job Description Job Title: QA Engineer (Security Testing / VAPT Exposure) Location: Mohali / Bangalore / Remote Experience: 25 Years Job Summary We are seeking a detail-oriented and proactive QA Engineer with hands-on experience in manual and automation testing and exposure to Vulnerability Assessment, Penetration Testing (VAPT), and Security Testing. The...


  • Delhi, India TAC Security Full time

    Job Description Job Description As a Security Engineer VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients...

  • AVP/VP-VAPT

    3 days ago


    Hyderabad, Telangana, India, Telangana NopalCyber Full time

    Role OverviewAs VP/AVP – Offensive security services, you will provide strategic and technical leadership for NopalCyber’s Offensive Security practice. You will lead and evolve core services such as Penetration Testing, Red Teaming, Application Security Assessments, BAS, AI Security and Threat Simulation. This role requires deep technical expertise,...

  • VAPT Engineer

    7 days ago


    Chennai, India Mizuho Full time

    Job Description Mizuho Global Services Pvt Ltd (MGS) is a subsidiary company of Mizuho Bank, Ltd, which is one of the largest banks or so called Mega Banks of Japan. MGS was established in the year 2020 as part of Mizuho's long term strategy of creating a captive global processing centre for remotely handling banking and IT related operations of Mizuho...


  • Bengaluru, Karnataka, India, Karnataka NTek Software Solutions Full time

    JOB DESCRIPTION : Position : Senior VAPT ConsultantExperience : 8+ yearsLoc : BengaluruCTC : 35 % Hike on current CTC Job type : Fulltime(Onsite)Job DescriptionWe are seeking an experienced and highly skilled Senior VAPT Consultant with 8+ years of hands-on experience in offensive security. The ideal candidate will possess deep technical expertise in...


  • Gurugram, Gurugram, India Delhivery Full time

    Job Description About Delhivery We are India's largest fully integrated logistics provider. We aim to build the operating system for commerce through a combination of world-class infrastructure, logistics operations of the highest quality and cutting-edge engineering and technology capabilities. Since its inception in 2011, our team has successfully...

  • Security Engineer

    2 weeks ago


    Delhi, India, India TAC Security Full time

    Job descriptionAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and...


  • Mumbai, India DripCapital Full time

    Job Description About Drip Capital We are a US-based fintech company revolutionizing global trade for SMEs. At Drip Capital, we're redefining the future of trade finance and facilitation, empowering small and medium-sized enterprises (SMEs) to scale internationally with ease. With the global SME trade market exceeding $5 trillion, our mission is to...


  • Mumbai, Maharashtra, India, Maharashtra TAC Security Full time

    Job descriptionAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and...