Job Title: VAPT Engineer - 3+ Years ExperienceJob Location: Thrissur Work from Office Mon - SatExperience: 3 - 5 yrsNotice Period: Immediate Joiners (need to join within 1-2 weeks)Job SummaryWe are looking for an experienced Vulnerability Assessment and Penetration Testing (VAPT) Engineer with 3+ years of experience in application and infrastructure security testing. The candidate will be responsible for identifying security vulnerabilities, performing penetration testing, preparing detailed reports, and supporting remediation activities.Key Responsibilities:Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, mobile applications, and infrastructure.Conduct black-box, grey-box, and white-box security testing based on project requirements.Identify and validate vulnerabilities such as:OWASP Top 10SQL InjectionCross-Site Scripting (XSS)Authentication and authorization issuesBroken access controlSSRFCSRFSecurity misconfigurationAPI vulnerabilitiesBusiness logic vulnerabilitiesPerform API security testing, including authentication, authorization, token validation, rate limiting, and API abuse scenarios.Conduct network and infrastructure VAPT, including server, network, firewall, and exposed services.Perform vulnerability scanning and manual validation using industry-standard tools.Analyze scan results and eliminate false positives through manual verification.Prepare detailed VAPT reports with vulnerability description, risk rating, evidence, business impact, and remediation recommendations.Work with development and infrastructure teams to support vulnerability remediation and retesting.Conduct security retesting to verify that identified vulnerabilities have been properly fixed.Maintain knowledge of emerging vulnerabilities, CVEs, attack techniques, and security best practices.Ensure testing activities comply with organizational security policies and applicable regulatory requirements.Required Technical Skills:Minimum 3 years of experience in VAPT / Cybersecurity / Application Security.Strong knowledge of OWASP Web and API Security.Experience with tools such as:o Burp Suiteo OWASP ZAPo Nmapo Nessus / Qualyso Metasploito SQLMapo PostmanGood understanding of:o HTTP/HTTPSo REST APIso JWT/OAuth/OIDCo TCP/IP and networkingo Linux and Windowso Web application architectureo Databases and SQLAbility to perform manual penetration testing, not just automated vulnerability scanning.Basic scripting knowledge in Python, PowerShell, Bash, or similar languages is desirable.Knowledge of cloud security, preferably Azure/Oracle Cloud/AWS, would be an advantage.Certifications - PreferredCEHOSCPeJPTCompTIA Security+CREST certificationsOther recognized cybersecurity/VAPT certificationsEducational Qualification:Bachelors degree in Computer Science, Information Technology, Cybersecurity, or a related field.Key Competencies:Strong analytical and problem-solving skills.Good understanding of security risks and their business impact.Ability to communicate vulnerabilities clearly to technical and business teams.Good documentation and report-writing skills.Ability to work independently as well as with development and infrastructure teams.