Lead Vulnerability Assessment and Penetration Testing

3 days ago


Kerala, India Art Technology and Software Full time ₹ 8,00,000 - ₹ 12,00,000 per year

Responsibilities

  • Client Engagement & Leadership
  • Act as a trusted security advisor for multiple high-value clients.
  • Manage end-to-end security assessment projects, including scoping, execution, reporting, and remediation guidance.
  • Conduct technical and executive-level briefings to communicate findings, risks, and strategic recommendations clearly.
  • Translate complex technical vulnerabilities into business risk insights to help clients prioritize actions.
  • Collaborate closely with client stakeholders to ensure security recommendations are practical and actionable.
  • Advanced Threat Modelling & Risk Assessment
  • Design and maintain threat models tailored to client applications, networks, and cloud environments.
  • Perform risk assessments focusing on business impact and likelihood of exploitation.
  • Develop attack scenarios based on the latest threat intelligence and real-world attacker techniques.
  • Guide clients in integrating security into their software development lifecycle (SDLC) and cloud infrastructure designs.
  • Penetration Testing & Red Team Operations
  • Lead advanced black-box, grey-box, and white-box penetration testing engagements for web applications, APIs, networks, and cloud environments.
  • Conduct sophisticated Red Team exercises to simulate targeted attack campaigns.
  • Design and develop custom exploits and testing tools to replicate specific attacker techniques.
  • Perform social engineering tests (phishing campaigns, physical security assessments) in controlled and ethical scenarios.
  • Provide detailed post-exercise analysis, including actionable remediation strategies and long term improvement plans.
  • Comprehensive Reporting & Documentation
  • Produce clear and technically thorough vulnerability assessment and penetration testing reports.
  • Create executive-level summaries focused on business impact and compliance risks.
  • Maintain structured and up-to-date testing methodologies and playbooks.
  • Contribute to internal knowledge base, documenting research, custom tools, and successful testing strategies.
  • Technical & Programming Expertise
  • Expert in vulnerability assessment and exploitation techniques across a wide range of technologies.
  • Proficient in security testing tools such as Burp Suite, Nessus, Metasploit, Nmap, OpenVAS, Cobalt Strike, Wireshark, and tcpdump.
  • Strong scripting and automation skills (Python, Bash, PowerShell) to automate repetitive testing tasks and tool workflows.
  • Capable of custom tool development and advanced exploit research to target unique client environments.
  • Strong knowledge of application security vulnerabilities (OWASP Top 10, SANS Top 25) and attack surface analysis.
  • In-depth understanding of cloud security risks, identity and access management, and container security (Docker, Kubernetes).
  • Social Engineering & OSINT Expertise
  • Design and execute social engineering and phishing simulations tailored to client environments.
  • Perform physical security assessments through tactics like tailgating and badge cloning.
  • Apply Open Source Intelligence (OSINT) techniques to gather reconnaissance data for assessments.
  • Provide training and awareness recommendations based on assessment outcomes.
  • Professional Attributes & Mindset
  • Strong analytical, problem-solving, and creative thinking skills.
  • Ethical hacker mindset with a continuous drive to research emerging threats, attack techniques, and defense bypass methods.
  • Methodical and detail-oriented approach to testing with the ability to think like an attacker.
  • Strong communication and presentation skills, able to engage both technical teams and business leadership.
  • Proactively innovate by developing new tools, scripts, or methodologies to improve testing efficiency and depth.

Qualifications

  • 7+ years of hands-on experience in Vulnerability Assessment, Penetration Testing, and security consulting.
  • Strong technical expertise in application security, network security, cloud security (AWS, Azure, GCP), and infrastructure security testing.
  • Proven experience using VAPT tools such as Burp Suite, Nessus, Qualys, Nmap, Metasploit, Nikto, OpenVAS, etc.
  • Solid knowledge of exploitation techniques, post-exploitation frameworks, and manual testing methodologies.
  • In-depth knowledge of web application vulnerabilities (OWASP Top 10) and network protocol analysis.
  • Experience conducting cloud security assessments, including misconfigurations, IAM permissions analysis, and container security.
  • Proficiency in scripting and automation (Python, Bash, PowerShell) to customize tests and tools.
  • Familiarity with security frameworks and standards such as NIST, ISO 27001, MITRE ATT&CK.
  • Strong reporting and documentation skills, able to translate technical findings into business friendly recommendations.
  • Excellent communication and stakeholder management skills, able to lead client-facing engagements.
  • Relevant certifications are a strong plus (e.g., OSCP, CREST, CISSP, CEH, GIAC GPEN).

Preferred Qualifications:

  • Certifications such as OSCP, GPEN, CREST CRT, CRTO are highly desirable.
  • Experience in DevSecOps, CI/CD pipeline security, or automated security testing frameworks.
  • Familiarity with industry compliance frameworks like PCI-DSS, GDPR, HIPAA, SOC2, and ISO 27001.
  • Prior consulting experience in a service delivery or customer-facing environment.
  • Experience with threat intelligence platforms and indicators of compromise (IoCs).

  • Senior Engineer

    2 weeks ago


    Kerala, India IBS Software Services Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Experience: 4–6 yearsLocation: Trivandrum/Cochin/Bangalore/ChennaiDepartment: Information Security / Offensive SecurityReports To: Senior Manager - Information SecurityRole OverviewWe are seeking a highly skilled and motivated Lead Offensive Security Engineer with 4–6 years of hands-on experience in offensive security and red/purple team engagements. The...

  • Naico ITS

    7 days ago


    Kerala, India Nexthire Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    Company - Naico ITS Position - Penetration TestingExperience - 5+ yearsLocation - Kochi ( 5 Days WFO) About Naico ITS : Naico ITS is a premier technology company specialized in providing custom engineered software solutions to business enterprises around the world. Naico was founded in mid-2005 by a team of highly accomplished US returned technology...


  • Kerala, India ValueMentor Infosec Private Limited (SEZ) Full time

    As a Virtual Chief Information Security Officer (vCISO), you will lead and manage the security operations function of organization. The role involves overseeing various aspects of security, disaster recovery, security finance management, documentation, compliance, and program onboarding. vCISO is expected to possess a diverse skill set encompassing...


  • Kakkanad, Kochi, Kerala, India WAHY LAB SOLUTIONS Full time

    **Job description**: - At Wahylab Solutions, we are at the forefront of digital security innovation. - As a trusted cybersecurity provider, we specialize in safeguarding businesses from online threats and vulnerabilities. - We are looking for enthusiastic and driven individuals to join our dynamic cybersecurity team as interns, where you will gain hands-on...

  • Analyst Iii

    7 hours ago


    Thiruvananthapuram, Kerala, India UST Full time

    Role Proficiency With strong knowledge and competence independently carry out the assigned tasks with minimal support from the supervisors Handle the internal audits to ensure the compliance requirements of various applicable standards and more independently handle VAPT Red Teaming assignments and involve in customer discussions to identify requirements...


  • Calicut, Kerala, India Branding Hut Full time

    **Job Overview**: **Key Responsibilities**: - Conduct training sessions on **Ethical Hacking, Network Security, Web Application Security, Penetration Testing, Cloud Security, and Cyber Threat Intelligence**. - Develop engaging course materials, presentations, case studies, and practical assignments. - Provide hands-on practical training using real-world...


  • Kochi, Kerala, India Eccetra Career Counseling Pvt.Ltd Full time

    Experience 0-2 years - To be positioned in the institution. - Connect with the Placement Cell of the institution and coordinate the dates and time for the psychometric Assessment. - Support in conducting the tests. Pay: ₹15,000.00 - ₹25,000.00 per month Schedule: - Monday to Friday Application Question(s): - Are you located in Palakkad,...


  • Level , Carnival Infopark, Inforpark, Kakkanad Kerala, Kochi, India MANUAL TESTING Full time US$ 60,000 - US$ 1,20,000 per year

    Job Summary: We are looking for a detail-oriented and experienced Senior QA Engineer with strong domain expertise in Auto Loans, Vehicle Financing, and Payments. The ideal candidate will have a solid background in both manual and automation testing, a deep understanding of API testing, and strong SQL skills for backend validation. You will be working...


  • Infopark-Kochi, Kochi, Kerala, India Avodha Edutech Pvt Ltd Full time

    Duration: 3 month with potential for regular employment upon successful completion. Avodha is seeking motivated and talented individuals for our cybersecurity internship program. This comprehensive, year-long internship offers hands-on experience in the field of cybersecurity and includes training and certifications. **Responsibilities**: Assist in...

  • Software Testing

    1 week ago


    Kerala, India UST Global Full time ₹ 5,00,000 - ₹ 15,00,000 per year

    As a Performance Test Engineer, you will be responsible for evaluating the responsiveness, stability, scalability, and speed of applications to ensure optimal performance under various conditions. Your key responsibilities will include: - Developing and executing load, stress, scalability, and endurance tests to assess application performance. - Analyzing...