Source description
About the role
VAPT Engineer Experience: 5 to 8 Years Function: Cyber Security / Vulnerability Assessment & Penetration Testing Work Location: Mumbai Job type: Contract to hire Role Summary: We are seeking an experienced and hands-on VAPT Engineer to lead and execute vulnerability assessment and penetration testing activities across applications, APIs, cloud workloads and enterprise technology environments. The role requires strong offensive security expertise, practical experience in Cloud security and the ability to identify, validate, prioritize and communicate security risks effectively to technical and business stakeholders. Key Responsibilities: Plan, conduct and report vulnerability assessments and penetration tests for web applications, APIs, mobile applications, cloud services and supporting infrastructure. Perform application and API security assessments aligned with OWASP Top 10, OWASP API Security Top 10, secure coding standards and industry best practices. Assess cloud environments for security misconfigurations, identity and access risks, exposed services, insecure storage, network security gaps and logging or monitoring weaknesses. Validate vulnerabilities through manual testing, exploitability analysis, proof-of concept development and risk-based prioritization. Prepare high-quality VAPT reports with clear risk ratings, business impact, evidence, technical details and actionable remediation guidance. Collaborate with application, infrastructure, DevOps, cloud and compliance teams to track remediation and verify closure of identified vulnerabilities. Support secure SDLC initiatives by reviewing application architecture, threat models, API designs and security controls during development and deployment phases. Mentor junior security engineers and provide technical guidance on penetration testing methodology, tools, reporting quality and remediation validation. Stay updated on emerging vulnerabilities, attack techniques, cloud threats, API abuse patterns and offensive security tooling. Required Skills and Experience 5 to 6 years of hands-on experience in vulnerability assessment, penetration testing, application security or offensive security roles. Strong practical experience in web application and API security testing, including authentication, authorization, session management, business logic, input validation, insecure direct object references and API abuse scenarios. Good understanding of Cloud security services and concepts, including Microsoft Entra ID, role-based access control, Key Vault, Storage Accounts, App Services, Cloud Functions, virtual networks, Network Security Groups and Monitor. Experience using tools such as Burp Suite, OWASP ZAP, Nmap, Nessus, Metasploit, Postman, SQLMap, Nikto, Dirsearch, uf and cloud security assessment tools. Ability to perform both automated and manual security testing and validate false positives effectively. Knowledge of common security standards and frameworks such as OWASP, NIST, CIS Benchmarks, ISO 27001, MITRE ATT&CK and PCI DSS security expectations. Strong understanding of TCP/IP, HTTP/HTTPS, REST APIs, OAuth, SAML, JWT, SSL/TLS, DNS, firewalls and basic infrastructure security concepts. Experience in preparing executive summaries, technical reports, remediation plans and vulnerability closure evidence. Strong communication, stakeholder management and team coordination skills suitable for Assistant Manager-level responsibilities. Education Requirement: Bachelors degree in Computer Science, Information Technology, Cyber Security, Engineering or a related field is required. Masters degree in Information Security, Cyber Security, Computer Science or a related discipline will be an added advantage. Preferred Certifications: OSCP or equivalent Offensive security certification is strongly preferred. CISSP, CSSLP, CEH, GPEN, GWAPT, PNPT or similar security certifications will be an added advantage. Cloud security certifications such as Microsoft Certified: Cloud Security Engineer Associate are desirable. Leadership and Managerial Expectations: Own end-to-end delivery of assigned VAPT engagements, including scoping, execution, reporting, stakeholder communication and closure tracking. Prioritize vulnerabilities based on risk, exploitability, business impact and exposure. Coordinate with internal technology teams and external vendors to ensure timely remediation. Contribute to process improvement, testing standards, reusable checklists, knowledge sharing and security governance reporting. Act as a technical escalation point for application and API security findings. Desired Candidate Profile: The ideal candidate should be a technically strong security professional with hands-on penetration testing experience, sound knowledge of cloud security and proven capability in application and API assessments. The candidate should be able to work independently, guide team members, communicate risks clearly and support remediation discussions with development, infrastructure and leadership teams. Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
More at Happiest Minds Technologies
Related open roles
LEAD INFORMATION TECHNOLOGY - Vulnerability Assessment
Delhi NCR
OT Security Architect
Bangalore · Mumbai · Delhi NCR
TECHNICAL LEAD - Vulnerability Mitigation
Bangalore
SENIOR EXECUTIVE INFORMATION SECURITY - Vulnerability Assessment
Delhi NCR
TECHNICAL LEAD - SOC Monitoring
Bangalore
MODULE LEAD - ServiceNow
Bangalore