Lead VAPT Engineer – Cybersecurity
6 days ago
Job Title
Lead VAPT Engineer – Cybersecurity & Risk Management
Position Overview
We are looking for a highly skilled and experienced Senior VAPT Engineer to join our cybersecurity team. The ideal candidate will lead vulnerability assessment and penetration testing activities, identify security weaknesses, and provide actionable recommendations to improve security posture. This role is critical in ensuring the resilience of our clients' applications, networks, and infrastructure against evolving cyber threats. The Lead VAPT Engineer will collaborate with cross-functional teams and deliver high-quality security assessments in a fast-paced, client-facing environment.
Key Responsibilities
Client Engagement & Leadership
- Act as a trusted security advisor for multiple high-value clients.
- Manage end-to-end security assessment projects, including scoping, execution, reporting,
and remediation guidance.
- Conduct technical and executive-level briefings to communicate findings, risks, and strategic recommendations clearly.
- Translate complex technical vulnerabilities into business risk insights to help clients prioritize actions.
- Collaborate closely with client stakeholders to ensure security recommendations are
practical and actionable.
Advanced Threat Modelling & Risk Assessment
- Design and maintain threat models tailored to client applications, networks, and cloud
environments.
- Perform risk assessments focusing on business impact and likelihood of exploitation.
- Develop attack scenarios based on the latest threat intelligence and real-world attacker
techniques.
- Guide clients in integrating security into their software development lifecycle (SDLC) and
cloud infrastructure designs.
Penetration Testing & Red Team Operations
- Lead advanced black-box, grey-box, and white-box penetration testing engagements for web
applications, APIs, networks, and cloud environments.
- Conduct sophisticated Red Team exercises to simulate targeted attack campaigns.
- Design and develop custom exploits and testing tools to replicate specific attacker
techniques.
- Perform social engineering tests (phishing campaigns, physical security assessments) in
controlled and ethical scenarios.
- Provide detailed post-exercise analysis, including actionable remediation strategies and long term improvement plans.
Comprehensive Reporting & Documentation
- Produce clear and technically thorough vulnerability assessment and penetration testing
reports.
- Create executive-level summaries focused on business impact and compliance risks.
- Maintain structured and up-to-date testing methodologies and playbooks.
- Contribute to internal knowledge base, documenting research, custom tools, and successful testing strategies.
Technical & Programming Expertise
- Expert in vulnerability assessment and exploitation techniques across a wide range of
technologies.
- Proficient in security testing tools such as Burp Suite, Nessus, Metasploit, Nmap, OpenVAS, Cobalt Strike, Wireshark, and tcpdump.
- Strong scripting and automation skills (Python, Bash, PowerShell) to automate repetitive
testing tasks and tool workflows.
- Capable of custom tool development and advanced exploit research to target unique client
environments.
- Strong knowledge of application security vulnerabilities (OWASP Top 10, SANS Top 25) and attack surface analysis.
- In-depth understanding of cloud security risks, identity and access management, and
container security (Docker, Kubernetes).
Social Engineering & OSINT Expertise
- Design and execute social engineering and phishing simulations tailored to client
environments.
- Perform physical security assessments through tactics like tailgating and badge cloning.
- Apply Open Source Intelligence (OSINT) techniques to gather reconnaissance data for
assessments.
- Provide training and awareness recommendations based on assessment outcomes.
Professional Attributes & Mindset
- Strong analytical, problem-solving, and creative thinking skills.
- Ethical hacker mindset with a continuous drive to research emerging threats, attack
techniques, and defense bypass methods.
- Methodical and detail-oriented approach to testing with the ability to think like an attacker.
- Strong communication and presentation skills, able to engage both technical teams and
business leadership.
- Proactively innovate by developing new tools, scripts, or methodologies to improve testing
efficiency and depth.
Preferred Qualifications
- Certifications such as OSCP, GPEN, CREST CRT, CRTO are highly desirable.
- Experience in DevSecOps, CI/CD pipeline security, or automated security testing frameworks.
- Familiarity with industry compliance frameworks like PCI-DSS, GDPR, HIPAA, SOC2, and ISO 27001.
- Prior consulting experience in a service delivery or customer-facing environment.
- Experience with threat intelligence platforms and indicators of compromise (IoCs).
Required Qualifications
- 7+ years of hands-on experience in Vulnerability Assessment, Penetration Testing, and
security consulting.
- Strong technical expertise in application security, network security, cloud security (AWS,
Azure, GCP), and infrastructure security testing.
- Proven experience using VAPT tools such as Burp Suite, Nessus, Qualys, Nmap, Metasploit, Nikto, OpenVAS, etc.
- Solid knowledge of exploitation techniques, post-exploitation frameworks, and manual
testing methodologies.
- In-depth knowledge of web application vulnerabilities (OWASP Top 10) and network protocol analysis.
- Experience conducting cloud security assessments, including misconfigurations, IAM
permissions analysis, and container security.
- Proficiency in scripting and automation (Python, Bash, PowerShell) to customize tests and
tools.
- Familiarity with security frameworks and standards such as NIST, ISO 27001, MITRE ATT&CK.
- Strong reporting and documentation skills, able to translate technical findings into business
friendly recommendations.
- Excellent communication and stakeholder management skills, able to lead client-facing
engagements.
- Relevant certifications are a strong plus (e.g., OSCP, CREST, CISSP, CEH, GIAC GPEN).
Skills: nikto,penetration testing,qualys,burp suite,vapt,cloud security,infrastructure security,vulnerability assessment,network security,nmap,nessus,openvas,metasploit,security consulting
-
Sr VAPT Engineer- Cybersecurity
4 days ago
Cochin, Kerala, India Art Technology and Software Full time ₹ 6,00,000 - ₹ 18,00,000 per yearWe are looking for a highly skilled and experienced Senior VAPT Engineer to join our cybersecurity team. The ideal candidate will lead vulnerability assessment and penetration testing activities, identify security weaknesses, and provide actionable recommendations to improve security posture. This role is critical in ensuring the resilience of our clients'...
-
Senior VAPT Engineer
2 weeks ago
Cochin, Kerala, India Art Technology and Software Full time ₹ 20,00,000 - ₹ 25,00,000 per yearPosition OverviewWe are looking for a highly skilled and experienced Senior VAPT Engineer to join our cybersecurity team. The ideal candidate will lead vulnerability assessment and penetration testing activities, identify security weaknesses, and provide actionable recommendations to improve security posture.Client Engagement & LeadershipThis role is...
-
Pre-Sales Engineer
15 hours ago
Cochin, Kerala, India Soffit Infrastructure Services (P) Ltd. Full time ₹ 2,40,000 - ₹ 4,20,000 per yearWe are seeking a proactive and detail-oriented Presales Engineer to support our cybersecurity practice. The role involves engaging with prospective clients, understanding their security requirements, preparing tailored proposals, coordinating with internal technical teams, and ensuring timely delivery of engagement documentation.This position bridges the gap...
-
Lead-Offensive Security
2 weeks ago
Cochin, Kerala, India Mantle Solutions Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob DescriptionTitle: Lead Offensive SecurityDepartment: Security Assurance TeamSummary: As a Lead Offensive Security, you will be part of the Security Assurance Team responsible for evaluating and strengthening Lulu Retails cybersecurity posture. This role contributes to the broader objectives of IT security, cyber resilience, and regulatory...
-
Lead – Offensive Security
2 weeks ago
Cochin, Kerala, India MantleSolutions Full time ₹ 12,00,000 - ₹ 36,00,000 per yearTitle: Lead – Offensive SecurityDepartment: Security Assurance TeamSummary: As a Lead – Offensive Security, you will be part of the Security Assurance Team responsible for evaluating and strengthening Lulu Retail's cybersecurity posture. This role contributes to the broader objectives of IT security, cyber resilience, and regulatory compliance.Essential...
-
Digital Workplace Engineer
2 weeks ago
Cochin, Kerala, India National Oilwell Varco Full time ₹ 12,00,000 - ₹ 36,00,000 per yearWe are seeking a Digital Workplace Engineer to lead the design, automation, and support of collaboration and productivity services across Microsoft 365, DocuSign, and ChatGPT Enterprise. This role requires deep technical expertise to ensure platform performance, security, and alignment with business objectives. Youll develop automation using PowerShell and...
-
GRC Lead
2 weeks ago
Cochin, Kerala, India Art Technology and Software Full time ₹ 20,00,000 - ₹ 25,00,000 per yearPosition SummaryThe GRC Lead will lead the strategic governance, risk management, and compliance agenda to strengthen the organization's cybersecurity resilience and ensure regulatory compliance. Acting as a key leader and collaborator, the GRC Lead will own the development, implementation, and continuous improvement of the GRC framework, ensuring alignment...
-
Junior Cyber Security Engineer
2 weeks ago
Cochin, Kerala, India Gadgeon Smart Systems Full time ₹ 8,00,000 - ₹ 12,00,000 per yearWe are seeking a motivated and technically curious Junior Cybersecurity Engineer to join our growing Cybersecurity team. This role is designed for recent graduates or early-career professionals who have completed relevant training or certifications and are eager to build a career in application, cloud, and DevSecOps security.Key Responsibilities:Support the...
-
Software Engineer
6 days ago
Cochin, Kerala, India NeST Digital Full time ₹ 8,00,000 - ₹ 16,00,000 per yearMinimum Required Experience : 5 yearsFull TimeSkillsthreat, vulnerabilities, security gapscyber security processesLinux/WindowsSTIG, vulnerabilities, CVE tracking, security gap analysisCybersecurity DomainDescriptionRoles : Cyber Security EngineerDetails of the project:we are creating a new pool of resources in CyberLab. This pool will have Privacy &...
-
Lead SOC
6 days ago
Cochin, Kerala, India Art Technology and Software Full time ₹ 8,00,000 - ₹ 12,00,000 per yearSOC LeadRole OverviewThe SOC Lead serves as a senior member of the Monitoring and Threat Detection function. This role focuses on high-quality incident triage, technical escalation management, continuous improvement of detection capabilities, and leading incident analysis across enterprise-wide environments. The SOC Lead mentors L1/L2 analysts, ensures SLA...