
Penetration Tester
1 week ago
**Key ResponsibilitiesA. VAPT Activities**
The VAPT should be comprehensive and include, but not be limited to:
- Network Scanning and Port Scanning
- System Identification and Trusted System Scanning
- Vulnerability and Malware Scanning
- Spoofing and Application Security Testing
- Access Control Mapping
- Denial of Service (DoS) Attack Simulation
- Password Cracking Techniques
- Cookie Security Assessment
- Functional Validation of Controls
- DMZ Architecture Review
- Firewall Rule Analysis
- Operating System Security Configuration Review
- Database Security Configuration Analysis
- Identification and Analysis of Complex Cyber-Attacks
**B. Website / Web Application Assessment**
Assessments should be performed as per the **latest OWASP Guidelines** and should cover:
- SQL Injection, CRLF Injection
- Cross Site Request Forgery (CSRF)
- Directory Traversal Vulnerabilities
- Authentication Exploits and Man-in-the-Middle Attacks
- Unvalidated Redirects and Forwards
- Password Strength Assessment
- JavaScript Security Scanning
- File Inclusion and Malicious File Execution
- Exploitable Vulnerabilities in Custom Code
- Web Server Security Assessment
- HTTP Injection
- Website Phishing Techniques
- Buffer Overflow Detection
- Input Validation Testing
- Insecure Storage and Social Engineering Attacks
**Standards & Methodologies**
- Follow industry best practices and **OWASP methodology**:
- Injection Flaws
- Broken Authentication
- Sensitive Data Exposure
- Cross-Site Scripting (XSS)
- Broken Access Control
- XML External Entities (XXE)
- Security Misconfiguration
- Insecure Deserialization
- Usage of Vulnerable Components
- Insufficient Logging & Monitoring
- Business Logic Vulnerabilities
- Provide detailed reports including:
- Risk Ratings and Remediation Plans
- Recommendations for Mitigation and Security Enhancements
**Eligibility Criteria**
- **Experience**: 3 to 9 years in VAPT, Cybersecurity, or related domains
- **Education**: Bachelor’s degree in Computer Science, Information Security, or related fields. Relevant certifications are a plus
- **Certifications Preferred**:
- CEH (Certified Ethical Hacker)
- OSCP (Offensive Security Certified Professional) preferred
- CISA / CISM / CISSP preferred
- CompTIA Security+, GIAC, or similar
**Required Tools & Technologies**
- **Burp Suite**:
- **Nessus / OpenVAS**:
- **Metasploit Framework**:
- **Nmap, Wireshark**:
- **Nikto, Acunetix**:
- **OWASP ZAP**:
- **Kali Linux or Parrot OS**:
- **Custom Scripting (Python, Bash, etc.)**
**Job Types**: Full-time, Permanent, Fresher
Pay: ₹600,000.00 - ₹1,500,000.00 per year
**Benefits**:
- Food provided
- Health insurance
- Leave encashment
- Paid sick time
- Paid time off
- Provident Fund
- Work from home
Schedule:
- Day shift
- Fixed shift
- Monday to Friday
Supplemental Pay:
- Performance bonus
- Yearly bonus
Work Location: In person
-
Penetration Tester
1 week ago
Gurugram, Haryana, India Saffron Networks Full time**Job Title**: VAPT Specialist (Vulnerability Assessment and Penetration Testing) **Location**: Gurgaon **Experience**: 1-2yrs **Employment Type**: Full-Time **Package-**2.5 LPA to 4 LPA **Key Responsibilities**: - Perform comprehensive vulnerability assessments and penetration tests. - Identify, analyze, and report security vulnerabilities. - Collaborate...
-
Application Security Professional
1 week ago
Gurgaon / Gurugram, Bengaluru / Bangalore, Hyderabad / Secunderabad, Telangana, India beBeePenetration Full time US$ 90,000 - US$ 1,20,000Job DescriptionWe are seeking an experienced penetration tester to join our team. The ideal candidate will have a strong understanding of various testing methodologies and tools, as well as a passion for uncovering vulnerabilities and identifying potential security risks.This position will play a critical role in helping clients prevent, detect, and respond...
-
Senior Security Tester
1 week ago
Delhi, Gurugram, NCR, India JINDAL STEEL & POWER Full time US$ 90,000 - US$ 1,20,000 per yearJob Description Security testing consultantJob Title: Application security testing consultant (Assistant Manager)Job SummaryWe are seeking an engineer with 3-5 yrs of experience and highly motivated senior security testing consultant to join our team in a dynamic industrial environment. The Application Security testing Engineer will be responsible for...
-
Information Security Analyst
7 days ago
Hyderabad / Secunderabad, Telangana, Gurgaon / Gurugram, Bengaluru / Bangalore, India beBeeSecurity Full time US$ 1,50,000 - US$ 2,00,000Job DescriptionOur organization seeks an accomplished penetration tester with expertise in manual and automated testing to join our Security Consulting department. The ideal candidate will have a strong understanding of various testing methodologies, tools, and passion for uncovering vulnerabilities and identifying security risks.This position plays a...