A technology security firm in Chennai, India is looking for a Security Analyst to enhance its security protocols. The role involves hands-on penetration testing, maintaining security controls across systems, and preparing detailed vulnerability reports. Candidates should have extensive knowledge of security vulnerabilities, DAST tools, and scripting in Python or Bash. Additional familiarity with regulatory frameworks and cloud services is essential. This position offers opportunities for continuous learning and professional growth.
Qualifications
Proven experience as a Security Analyst, Security Engineer, or Penetration Tester.
Hands-on experience with manual penetration testing and DAST tools/techniques.
Strong understanding of common vulnerabilities and attack vectors.
Responsibilities
Implement and maintain security controls across cloud infrastructure and web applications.
Perform regular vulnerability scans and hands-on penetration testing.
Prepare clear, detailed vulnerability reports with risk-based analysis.
Skills
Manual penetration testing
DAST tools/techniques
Python scripting
Vulnerability management
Business applications security
Network protocols
TLS understanding
Tools
Kali Linux
Metasploit
Burp Suite
Nmap
Wireshark
Job description
Proven experience as a Security Analyst, Security Engineer, or Penetration Tester
Strong understanding of securing corporate environments and business applications
Hands‑on experience with manual penetration testing and DAST tools/techniques
Ability to analyze scan results and recommend clear remediation or mitigation plans
Working knowledge of penetration testing tools and platforms (Kali Linux, Metasploit, Burp Suite, Nmap, Wireshark)
Strong understanding of common vulnerabilities and attack vectors (SQL Injection, XSS, buffer overflows) and their mitigations
Familiarity with standards and frameworks such as OWASP, CVE, CWE, SANS and NIST
Understanding of Transport Layer Security (TLS) and secure communication mechanisms
Foundational knowledge of hosting platforms, public cloud services, and enterprise networking
Familiarity with secure coding practices and vulnerability management frameworks (OWASP)
Proficiency in Python or Bash scripting for automation and security tasks
Familiarity with network protocols and encryption concepts
Understanding of regulatory and compliance frameworks (PCI DSS, GDPR)
Continuous learning mindset with curiosity to explore new tools and techniques (HTB, TryHackMe, labs, self-learning)
Security Engineering & Implementation
Implement and maintain security controls across cloud infrastructure, web applications, and internal systems
Support secure configuration of services, including access controls, secrets management, and API security
Review and strengthen components related to identity, authentication, and transaction workflows
Perform regular vulnerability scans and hands‑on penetration testing
Identify and exploit security weaknesses using both manual and automated techniques
Develop and execute structured testing methodologies and test plans
Participate in threat modelling exercises and security design reviews for new features and system changes
Identify risks and misconfigurations and partner with engineers to remediate them
Track emerging vulnerabilities and evolving attack techniques
Reporting & Remediation
Prepare clear, detailed vulnerability reports with risk‑based analysis
Validate the effectiveness of implemented fixes
Reduce false positives from tool‑generated reports
Communicate findings and remediation guidance to both technical and non‑technical stakeholders
Work closely with engineering and product teams to embed security into everyday development
Act as a trusted security advisor during application design and delivery