Penetration Tester
4 days ago
**Key ResponsibilitiesA. VAPT Activities**
The VAPT should be comprehensive and include, but not be limited to:
- Network Scanning and Port Scanning
- System Identification and Trusted System Scanning
- Vulnerability and Malware Scanning
- Spoofing and Application Security Testing
- Access Control Mapping
- Denial of Service (DoS) Attack Simulation
- Password Cracking Techniques
- Cookie Security Assessment
- Functional Validation of Controls
- DMZ Architecture Review
- Firewall Rule Analysis
- Operating System Security Configuration Review
- Database Security Configuration Analysis
- Identification and Analysis of Complex Cyber-Attacks
**B. Website / Web Application Assessment**
Assessments should be performed as per the **latest OWASP Guidelines** and should cover:
- SQL Injection, CRLF Injection
- Cross Site Request Forgery (CSRF)
- Directory Traversal Vulnerabilities
- Authentication Exploits and Man-in-the-Middle Attacks
- Unvalidated Redirects and Forwards
- Password Strength Assessment
- JavaScript Security Scanning
- File Inclusion and Malicious File Execution
- Exploitable Vulnerabilities in Custom Code
- Web Server Security Assessment
- HTTP Injection
- Website Phishing Techniques
- Buffer Overflow Detection
- Input Validation Testing
- Insecure Storage and Social Engineering Attacks
**Standards & Methodologies**
- Follow industry best practices and **OWASP methodology**:
- Injection Flaws
- Broken Authentication
- Sensitive Data Exposure
- Cross-Site Scripting (XSS)
- Broken Access Control
- XML External Entities (XXE)
- Security Misconfiguration
- Insecure Deserialization
- Usage of Vulnerable Components
- Insufficient Logging & Monitoring
- Business Logic Vulnerabilities
- Provide detailed reports including:
- Risk Ratings and Remediation Plans
- Recommendations for Mitigation and Security Enhancements
**Eligibility Criteria**
- **Experience**: 3 to 9 years in VAPT, Cybersecurity, or related domains
- **Education**: Bachelor’s degree in Computer Science, Information Security, or related fields. Relevant certifications are a plus
- **Certifications Preferred**:
- CEH (Certified Ethical Hacker)
- OSCP (Offensive Security Certified Professional) preferred
- CISA / CISM / CISSP preferred
- CompTIA Security+, GIAC, or similar
**Required Tools & Technologies**
- **Burp Suite**:
- **Nessus / OpenVAS**:
- **Metasploit Framework**:
- **Nmap, Wireshark**:
- **Nikto, Acunetix**:
- **OWASP ZAP**:
- **Kali Linux or Parrot OS**:
- **Custom Scripting (Python, Bash, etc.)**
**Job Types**: Full-time, Permanent, Fresher
Pay: ₹600,000.00 - ₹1,500,000.00 per year
**Benefits**:
- Food provided
- Health insurance
- Leave encashment
- Paid sick time
- Paid time off
- Provident Fund
- Work from home
Schedule:
- Day shift
- Fixed shift
- Monday to Friday
Supplemental Pay:
- Performance bonus
- Yearly bonus
Work Location: In person
-
Penetration Tester
4 days ago
Gurugram, Haryana, India Saffron Networks Full time**Job Title**: VAPT Specialist (Vulnerability Assessment and Penetration Testing) **Location**: Gurgaon **Experience**: 1-2yrs **Employment Type**: Full-Time **Package-**2.5 LPA to 4 LPA **Key Responsibilities**: - Perform comprehensive vulnerability assessments and penetration tests. - Identify, analyze, and report security vulnerabilities. - Collaborate...
-
Gurugram, India Deloitte Full timeDear Connections,We have scheduled hiring drive at Gurgaon DLF office on 1st Nov'25 (Saturday).Interested applicants kindly apply using the link - https://southasiacareers.deloitte.com/job-invite/90792/Please refer the below JD for ready reference :-Your potential, unleashed.India’s impact on the global economy has increased at an exponential rate and...
-
Gurugram, India Deloitte Full timeDear Connections,We have scheduled hiring drive at Gurgaon DLF office on 1st Nov'25 (Saturday).Interested applicants kindly apply using the link - https://southasiacareers.deloitte.com/job-invite/90792/Please refer the below JD for ready reference :-Your potential, unleashed.India’s impact on the global economy has increased at an exponential rate and...
-
Gurugram, India Deloitte Full timeDear Connections, We have scheduled hiring drive at Gurgaon DLF office on 1st Nov'25 (Saturday). Interested applicants kindly apply using the link - https://southasiacareers.deloitte.com/job-invite/90792/ Please refer the below JD for ready reference :- Your potential, unleashed. India’s impact on the global economy has increased at an exponential rate and...
-
Gurugram, India Amazon Full timeWe're on a journey to build something new! Come join our team and build new discovery and shopping products that connect customers with their vehicle of choice. We're looking for a talented Software Dev Engineer II-TEST to join our team of product managers, designers, and engineers to conceive, design, and develop innovative automotive-shopping experiences...
-
Software Dev Engineer II-TEST, Amazon Autos
1 week ago
Gurugram, India Amazon Full timeThis job is with Amazon, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.DESCRIPTION: We're on a journey to build something new! Come join our team and build new discovery and shopping products that connect customers with their vehicle of choice....
-
Web Application Firewall Engineer
2 days ago
Bengaluru, Gurugram, India Carelon Global Solution Full time ₹ 12,00,000 - ₹ 24,00,000 per yearABOUT ELEVANCE HEALTHElevance Health is a leading health company in America dedicated to improving lives and communities and making healthcare simpler. It is the largest managed health care company in the Blue Cross Blue Shield (BCBS) Association serving more than 45 million lives across 14 states.A regular in Fortune 500 list, Elevance Health ranked 20 in...