Source description
About the role
Key Responsibilities: - Develop and maintain security test plans, test methods, test suites, and test scripts in line with regulatory and industry best practices. - Review test design specifications and ensure complete coverage of potential vulnerabilities and threat vectors. - Perform manual and automated security testing of web, mobile, API, and infrastructure components. - Conduct VAPT on Web/Mobile/ API and IT Infra devices. - Conduct Configuration audits on IT Infra devices. - Use industry-recognized tools such as Burp Suite, Nmap, Wireshark, Metasploit, Nessus, etc. - Simulate attacks to identify and analyze potential security weaknesses in systems and applications. - Collaborate with clients and internal stakeholders to ensure project execution. - Analyze applications beyond technical vulnerabilities to uncover logic errors, workflow bypasses, and scenario-specific scenarios. - Ensure adherence to relevant standards such as OWASP Top 10, SANS 25, ISO 27001. - Prepare detailed test reports, including risk severity, PoCs, and recommendations. - Collaborate with client development teams to explain identified vulnerabilities and ensure clear communication of findings to both technical and non-technical stakeholders. Required Qualifications: Academic Qualifications: - B.Tech / M.Tech in Computer Science, IT, or related discipline - BCA / MCA or other equivalent qualifications Professional Certifications: - CEH (Certified Ethical Hacker) - OSCP/OSCP+ - ISO 27001 - ISO 17025 - CISA - CISSP Desired Skills & Competencies: - Strong knowledge of network protocols, firewalls, cloud configurations, and overall application architecture. - Solid understanding of application code structures and how they relate to security vulnerabilities. - Proven experience with security testing methodologies, frameworks, and vulnerability standards (OWASP, CWE/SANS, NIST, etc.). - Valuable understanding of cyberattack vectors, exploit techniques, and threat modelling practices. - Familiarity with scripting languages (e.g., Python, Bash) for automation and custom testing is an advantage. - Excellent analytical, documentation, reporting, and communication skills. - Ability to work independently, mentor junior engineers, and manage testing priorities in a fast-paced environment. - Awareness of cloud security, zero trust architecture, and other emerging security concepts is an added advantage. .