Vulnerability Assessment

2 months ago


Gurugram, India Milliman Full time

Job Summary:

We are seeking a highly skilled Vulnerability Assessment and Penetration Testing (VAPT) Analyst in a GCS India IT team with a minimum of 4 years of experience in the Application Security field. The ideal candidate will possess a comprehensive understanding of application penetration testing, secure Software Development Life Cycle (SDLC) design, and a robust knowledge of Vulnerability Management. The position involves performing application security assessments, assisting with security best practices, and conducting thorough Vulnerability Assessments and Penetration Testing.

Primary Duties & Responsibilities:

Conduct application-level penetration testing, as well as Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST), to identify vulnerabilities. Perform secure code reviews and contribute to secure SDLC design to ensure the development of resilient applications. Identify and exploit vulnerabilities in applications and infrastructure to simulate real-world cyber threats. Execute Vulnerability Management (VM) plans, coordinating, monitoring, and supporting activities related to security patching, configuration management, and attack surface management. Facilitate and coordinate vulnerability assessments and scans, review assessment results, and oversee remediation activities for network and infrastructure devices. Configure and maintain regular and ad-hoc vulnerability scans against internal and external IT infrastructure. Demonstrate proficiency in standards such as ISO 27001, PCI DSS, NIST, and OWASP to ensure compliance and adherence to best practices. Utilize tools such as BurpSuite, Nessus, NMap, Kali Linux, Qualys, and Nessus for effective vulnerability assessment and penetration testing. Develop and maintain detailed technical documentation, including design documents, test plans, project plans, and procedures. Collaborate with stakeholders to plan, track, schedule, and execute assessments effectively. Utilize problem-solving, planning, and analytical skills to drive continuous improvement in VAPT processes. Interact with stakeholders in a collaborative manner to deliver results, provide feedback, and offer remediation recommendations based on findings. Demonstrate excellent analytical, communication, and problem-solving skills in all aspects of the role.

Required Skills & Attributes:

Minimum of 4 years of experience in Application Security, Vulnerability Assessment, and Penetration Testing. In-depth understanding of OWASP Top 10 vulnerabilities and their mitigation strategies. Strong experience in conducting application-level testing using SAST and DAST techniques. Proficiency in vulnerability management processes and tools such as Qualys and Nessus. Familiarity with industry standards and frameworks such as ISO 27001, PCI DSS, NIST, and OWASP. Hands-on experience with penetration testing tools like BurpSuite, NMap, Kali Linux, etc. Excellent written and verbal communication skills, with the ability to convey technical concepts to both technical and non-technical stakeholders. Proven ability to work collaboratively in a team environment and independently when required.

Required Qualifications:

Bachelor's degree in Computer Science/information technology or other related degree. Relevant certifications such as CEH, OSCP, CISSP, or equivalent are preferred.

  • gurugram, India Milliman Full time

    Job Summary: We are seeking a highly skilled Vulnerability Assessment and Penetration Testing (VAPT) Analyst in a GCS India IT team with a minimum of 4 years of experience in the Application Security field. The ideal candidate will possess a comprehensive understanding of application penetration testing, secure Software Development Life Cycle (SDLC)...

  • Lead Engineer

    4 weeks ago


    gurugram, India Silverskills Private Limited Full time

    Job Description of the role : - Leads the implementation and delivery of VA/PT tools and services for our global clients.Responsibilities : - Daily assessment of vulnerabilities identified by infrastructure scan.- Assist in the responsibility for the reviewing vulnerabilities' data from multiple sources (i.e., external / internal penetration testing,...

  • Lead Engineer

    4 weeks ago


    Gurugram, India Silverskills Private Limited Full time

    Job Description of the role : - Leads the implementation and delivery of VA/PT tools and services for our global clients.Responsibilities :- Daily assessment of vulnerabilities identified by infrastructure scan.- Assist in the responsibility for the reviewing vulnerabilities' data from multiple sources (i.e., external / internal penetration testing,...

  • Lead Engineer

    4 weeks ago


    Gurgaon/Gurugram, India Silverskills Private Limited Full time

    Job Description of the role : - Leads the implementation and delivery of VA/PT tools and services for our global clients.Responsibilities : - Daily assessment of vulnerabilities identified by infrastructure scan.- Assist in the responsibility for the reviewing vulnerabilities' data from multiple sources (i.e., external / internal penetration...

  • Lead Engineer

    1 month ago


    Gurgaon/Gurugram, IN Silverskills Private Limited Full time

    Job Description of the role : - Leads the implementation and delivery of VA/PT tools and services for our global clients.Responsibilities :- Daily assessment of vulnerabilities identified by infrastructure scan.- Assist in the responsibility for the reviewing vulnerabilities' data from multiple sources (i.e., external / internal penetration testing,...


  • Gurugram, India Aceseekers Full time

    Location - Hyderabad, Mumbai, Bangalore, Gurgaon, Chennai, Pune, Kolkata (Hybrid Mode)Total Experience - 5 YearsRelevant Experience - 3-8 YearsShift Timing - 11AM - 8PMPrimary skills - vulnerability & assessment management, VM implementation, CIS Baseline.tools like rapid 7 , tenable , qualys guard ( certifications are added advantage )Certifications - CISSP...


  • gurugram, India Aceseekers Full time

    Location - Hyderabad, Mumbai, Bangalore, Gurgaon, Chennai, Pune, Kolkata (Hybrid Mode)Total Experience - 5 YearsRelevant Experience - 3-8 YearsShift Timing - 11AM - 8PMPrimary skills - vulnerability & assessment management, VM implementation, CIS Baseline.tools like rapid 7 , tenable , qualys guard ( certifications are added advantage )Certifications - CISSP...

  • Security Architect

    5 days ago


    gurugram, India Egon Zehnder - Knowledge Center India Full time

    Egon Zehnder is trusted partner to many of the world's most respected organizations and is a leading leadership advisory firm, with more than 560+ consultants and 63 offices in 36 countries spanning Europe, the Americas, Asia Pacific, the Middle East and Africa. Our clients range from the largest corporations to emerging growth companies, government and...

  • Security Architect

    5 days ago


    Gurugram, India Egon Zehnder - Knowledge Center India Full time

    Egon Zehnder is trusted partner to many of the world's most respected organizations and is a leading leadership advisory firm, with more than 560+ consultants and 63 offices in 36 countries spanning Europe, the Americas, Asia Pacific, the Middle East and Africa. Our clients range from the largest corporations to emerging growth companies, government and...

  • Security Architect

    5 days ago


    Gurgaon/Gurugram, India Egon Zehnder - Knowledge Center India Full time

    Egon Zehnder is trusted partner to many of the world's most respected organizations and is a leading leadership advisory firm, with more than 560+ consultants and 63 offices in 36 countries spanning Europe, the Americas, Asia Pacific, the Middle East and Africa. Our clients range from the largest corporations to emerging growth companies, government and...


  • Gurugram, Haryana, India Ameriprise India Full time

    This position primarily supports the Vendor Risk Assessment Team. Will possess appropriate content knowledge for the Company on physical security regulatory mandates as they relate to vendor due diligence. Prioritizing, managing multiple tasks, effective case reporting and documentation. Performs security risk assessments based on vulnerability criteria to...


  • Mumbai/Bangalore/Hyderabad/Gurgaon/Gurugram/Chennai/Pune/Kolkata, India Aceseekers Full time

    Job Description : We are seeking a highly skilled and experienced Cybersecurity Analyst with expertise in Rapid7 products to join our team. The ideal candidate will have 3-4 years of hands-on experience working with Rapid7 solutions and a strong background in cybersecurity. In this role, you will be responsible for implementing, configuring, and managing...


  • Mumbai/Bangalore/Hyderabad/Gurgaon/Gurugram/Chennai/Pune/Kolkata, IN Aceseekers Full time

    Job Description :We are seeking a highly skilled and experienced Cybersecurity Analyst with expertise in Rapid7 products to join our team. The ideal candidate will have 3-4 years of hands-on experience working with Rapid7 solutions and a strong background in cybersecurity. In this role, you will be responsible for implementing, configuring, and managing...


  • Hyderabad/Mumbai/Bangalore/Chennai/Pune/Gurgaon/Gurugram/Kolkata, India Aceseekers Full time

    Location - Hyderabad, Mumbai, Bangalore, Gurgaon, Chennai, Pune, Kolkata (Hybrid Mode)Total Experience - 5 YearsRelevant Experience - 3-8 YearsShift Timing - 11AM - 8PMPrimary skills - vulnerability & assessment management, VM implementation, CIS Baseline.tools like rapid 7 , tenable , qualys guard ( certifications are added advantage )Certifications - CISSP...


  • Hyderabad/Mumbai/Bangalore/Chennai/Pune/Gurgaon/Gurugram/Kolkata, IN Aceseekers Full time

    Location - Hyderabad, Mumbai, Bangalore, Gurgaon, Chennai, Pune, Kolkata (Hybrid Mode)Total Experience - 5 YearsRelevant Experience - 3-8 YearsShift Timing - 11AM - 8PMPrimary skills - vulnerability & assessment management, VM implementation, CIS Baseline.tools like rapid 7 , tenable , qualys guard ( certifications are added advantage )Certifications - CISSP...

  • Infosec Consultant

    1 month ago


    Gurugram, India Xiarch Solutions Pvt Ltd Full time

    Xiarch is a CERTEmpanelledOrganization .Xiarch is an acronym for Xtreme InfoSec AuditorsResearchers Consultants and Hackers. Xiarch is best of breedprofessionals in the infosec industry. Xiarch aspires to use itsmoral values competence and knowledge to secure the corporate ITinvestments and help the our clients derisk their business. Xiarchhas its own R & D...

  • Infosec Consultant

    1 month ago


    gurugram, India Xiarch Solutions Pvt Ltd Full time

    Xiarch is a CERTEmpanelledOrganization .Xiarch is an acronym for Xtreme InfoSec AuditorsResearchers Consultants and Hackers. Xiarch is best of breedprofessionals in the infosec industry. Xiarch aspires to use itsmoral values competence and knowledge to secure the corporate ITinvestments and help the our clients derisk their business. Xiarchhas its own R & D...


  • Gurugram, India DriveSec Technologies Full time

    Company Description DriveSec Technologies is a leading organization that empowers and enables companies to drive security and enhance workplace, infrastructure, and technological security processes. Our mission is to bridge the gap between technical teams and business teams, fostering a shift-left culture and mindset for secure growth. We prioritize a...


  • Gurugram, India DriveSec Technologies Full time

    Company Description DriveSec Technologies is a leading organization that empowers and enables companies to drive security and enhance workplace, infrastructure, and technological security processes. Our mission is to bridge the gap between technical teams and business teams, fostering a shift-left culture and mindset for secure growth. We prioritize a...


  • Gurugram, India Aceseekers Full time

    Job Description : We are seeking a highly skilled and experienced API Security Penetration Tester to join our cybersecurity team. The ideal candidate will have 3-4 years of hands-on experience conducting penetration testing on APIs and a strong background in cybersecurity. In this role, you will be responsible for assessing the security of our...