Job Title: VAPT Engineer - 3+ Years Experience
Job Location: Thrissur | Work from Office | Mon - Sat
Experience: 3 - 5 yrs
Notice Period: Immediate Joiners (need to join within 1-2 weeks)
Job Summary
We are looking for an experienced Vulnerability Assessment and Penetration Testing (VAPT) Engineer with 3+ years of experience in application and infrastructure security testing. The candidate will be responsible for identifying security vulnerabilities, performing penetration testing, preparing detailed reports, and supporting remediation activities.
Key Responsibilities:
Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, mobile applications, and infrastructure.
Conduct black-box, grey-box, and white-box security testing based on project requirements.
Identify and validate vulnerabilities such as:
OWASP Top 10
SQL Injection
Cross-Site Scripting (XSS)
Authentication and authorization issues
Broken access control
SSRF
CSRF
Security misconfiguration
API vulnerabilities
Business logic vulnerabilities
Perform API security testing, including authentication, authorization, token validation, rate limiting, and API abuse scenarios.
Conduct network and infrastructure VAPT, including server, network, firewall, and exposed services.
Perform vulnerability scanning and manual validation using industry-standard tools.
Analyze scan results and eliminate false positives through manual verification.
Prepare detailed VAPT reports with vulnerability description, risk rating, evidence, business impact, and remediation recommendations.
Work with development and infrastructure teams to support vulnerability remediation and retesting.
Conduct security retesting to verify that identified vulnerabilities have been properly fixed.
Maintain knowledge of emerging vulnerabilities, CVEs, attack techniques, and security best practices.
Ensure testing activities comply with organizational security policies and applicable regulatory requirements.
Required Technical Skills:
Minimum 3 years of experience in VAPT / Cybersecurity / Application Security.
Strong knowledge of OWASP Web and API Security.
Experience with tools such as:
o Burp Suite
o OWASP ZAP
o Nmap
o Nessus / Qualys
o Metasploit
o SQLMap
o Postman
Good understanding of:
o HTTP/HTTPS
o REST APIs
o JWT/OAuth/OIDC
o TCP/IP and networking
o Linux and Windows
o Web application architecture
o Databases and SQL
Ability to perform manual penetration testing, not just automated vulnerability scanning.
Basic scripting knowledge in Python, PowerShell, Bash, or similar languages is desirable.
Knowledge of cloud security, preferably Azure/Oracle Cloud/AWS, would be an advantage.
Certifications - Preferred
CEH
OSCP
eJPT
CompTIA Security+
CREST certifications
Other recognized cybersecurity/VAPT certifications
Educational Qualification:
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Key Competencies:
Strong analytical and problem-solving skills.
Good understanding of security risks and their business impact.
Ability to communicate vulnerabilities clearly to technical and business teams.
Good documentation and report-writing skills.
Ability to work independently as well as with development and infrastructure teams.
Experience
3 - 6 Years
No. of Openings
3
Education
Graduate
Role
VAPT Engineer
Industry Type
IT Services & Consulting
Gender
[ Male / Female ]
Job Country
India
Type of Job
Full Time
Work Location Type
Work from Office