Cyber Security Analyst

Quess Corp Limited

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Quess Corp Limited is seeking a Cyber Security Analyst – Application & Infrastructure Security to identify, validate, and remediate vulnerabilities across applications, networks, and cloud. The role requires collaboration with development, infrastructure, and cloud teams to ensure timely remediation and secure releases.

The ideal candidate has 5–8 years in cybersecurity, strong knowledge of OWASP Top 10, vulnerability assessment, and remediation practices, with experience in testing web,

Qualifications

  • Bachelor’s degree in Computer Science, IT, Cybersecurity, or related discipline.
  • 5–8 years of experience in cybersecurity, VAPT, app/infrastructure security.
  • Experience with application development and/or infrastructure teams.
  • Experience managing vulnerability remediation through to closure.
  • Experience in app, network, infra, or cloud security testing.

Responsibilities

  • Identify, assess, and prioritize vulnerabilities across apps, networks, and cloud.
  • Conduct security testing of web/mobile apps and APIs across SDLC.
  • Coordinate remediation with development and infrastructure teams.
  • Validate vulnerability closures with retests and evidence collection.
  • Maintain vulnerability registers and periodic risk-based reporting.

Skills

Application security
OWASP Top 10
Vulnerability assessment
Network security
Cloud security

Education

Bachelor's degree in CS/IT/CYB

Tools

Burp Suite
Nessus/Tenable
Qualys
Nmap

Job description

Job Description — Cyber Security Analyst


About the Role

Position: Cyber Security Analyst – Application & Infrastructure Security


Experience: 5–8 years


Reporting To: Head of IT


1. Role Overview

We are looking for a Cyber Security Analyst (VAPT) responsible for identifying, assessing, prioritizing, and validating security vulnerabilities across the organization's applications, network, infrastructure, and technology environments. The role will work closely with application development, infrastructure, network, cloud, and technology teams to ensure identified vulnerabilities are appropriately assessed, remediated within agreed timelines, and independently validated through security retesting. The candidate should be able to translate technical vulnerabilities into business and technology risk, prioritize remediation based on impact, and provide practical guidance to technical teams on vulnerability closure.


2. Key Responsibilities

A. Application Security Testing


  • Perform security testing of applications across the SDLC.

  • Conduct vulnerability assessments and security testing of:

  • Web applications

  • Mobile applications

  • APIs

  • Microservices

  • Application infrastructure

  • Review security testing reports and validate identified vulnerabilities.

  • Assess vulnerabilities based on severity, exploitability, business criticality, exposure, and potential impact.

  • Work with development teams to understand the root cause of vulnerabilities and recommend appropriate remediation approaches.

  • Support security testing as part of application releases and major changes.


B. Network & Infrastructure Security Testing


  • Perform and/or coordinate security assessments of:

  • Servers

  • Databases

  • Cloud infrastructure

  • Internet-facing infrastructure

  • Review vulnerability assessment and penetration testing reports.

  • Validate identified infrastructure and network vulnerabilities.

  • Work with infrastructure/network teams to determine appropriate remediation actions.

  • Assess vulnerabilities considering asset criticality, exposure, exploitability, and potential business impact.


C. Vulnerability Risk Assessment & Prioritization


  • Establish risk-based prioritization of identified vulnerabilities.

  • Prioritize remediation based on factors such as:

  • Business criticality

  • Data sensitivity

  • Availability of known exploits

  • Potential business impact

  • Compensating controls

  • Recommend appropriate remediation timelines based on risk.

  • Identify vulnerabilities requiring immediate escalation to management.

  • Distinguish between technical severity and actual business risk.


D. Vulnerability Remediation & Closure


  • Work closely with application, infrastructure, cloud, network, and database teams to drive vulnerability remediation.

  • Provide technical guidance to teams on possible remediation approaches.

  • Review proposed remediation plans and assess whether they adequately address the identified vulnerability.

  • Track remediation progress and follow up on overdue or high-risk vulnerabilities.

  • Support technical teams in resolving complex or recurring vulnerabilities.

  • Escalate vulnerabilities that remain unresolved beyond agreed risk timelines.


E. Security Retesting & Validation


  • Perform security retesting after remediation.

  • Validate whether the vulnerability has been fully resolved.

  • Confirm that remediation has not introduced new security issues.

  • Review evidence provided by technical teams where appropriate.

  • Formally confirm vulnerability closure only after satisfactory validation.

  • Maintain appropriate records of testing, remediation, and closure evidence.


F. Security Governance & Reporting


  • Maintain vulnerability registers and remediation status.

  • Prepare periodic reports on:

  • Provide security risk updates to Cyber Security leadership and relevant technology stakeholders.

  • Support security audits, compliance assessments, and regulatory requirements


Qualifications

5. Qualifications & Experience


  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related discipline.

  • 5–8 years of experience in cybersecurity, VAPT, application security, infrastructure security.

  • Experience working with application development and / or infrastructure teams.

  • Experience managing vulnerability remediation through to closure.

  • Experience in application, network, infrastructure, or cloud security testing.


Required Skills

The candidate should have good practical knowledge of:



  • Application security and common web/API vulnerabilities.

  • OWASP Top 10 and secure application development concepts.

  • Vulnerability assessment and penetration testing methodologies.

  • Network and infrastructure security fundamentals.

  • Operating system, database, network, and cloud security concepts.

  • Vulnerability management and risk-based prioritization.

  • Common vulnerability scoring concepts such as CVSS and exploitability assessment.

  • Security testing tools such as Burp Suite, Nessus/Tenable, Qualys, Nmap, or equivalent.

  • Basic understanding of SIEM, EDR, WAF, firewall, IAM, and endpoint security technologies.

  • Ability to interpret technical security reports and translate findings into actionable remediation requirements.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

Certbar Security • Mumbai

On-site
INR 600,000 - 1,200,000
Technical Lead-Cybersecurity
Technical Lead-Cybersecurity

Birlasoft • Dadri

On-site
INR 1,200,000 - 2,400,000
Cyber Security Consultant
Cyber Security Consultant

Infosys • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Cyber Security Expert
Cyber Security Expert

Fluentgrid Limited • Visakhapatnam

On-site
INR 1,200,000 - 1,800,000
Security Vulnerability Analyst
Security Vulnerability Analyst

Experian Group • Hyderabad

On-site
INR 1,200,000 - 2,400,000
VAPT Security Engineer
VAPT Security Engineer

Zohorecruit • Hyderabad

Hybrid
INR 1,800,000 - 2,800,000
Cyber Analysts - Vulnerability Management and Penetration Testing
Cyber Analysts - Vulnerability Management and Penetration Testing

Tata Power • Navi Mumbai, Mumbai

On-site
INR 800,000 - 1,400,000
Security Analyst - VAPT
Security Analyst - VAPT

TechDefence Labs • Delhi

On-site
INR 700,000 - 1,000,000
Competitive salary and benefits package
Opportunities for continuous learning
Cyber Security Analyst
Cyber Security Analyst

Network Intelligence India • Thane

On-site
INR 900,000 - 1,700,000