Esyasoft Technologies Private Limited | Full time
Principal Software Engineer - Cybersecurity (VAPT)
- Job Designation Principal Software Engineer
- Work Experience 2 to 5 years
- Relevant Experience (Years) 2 to 5 years
- Required Skills
- it security
- penetration testing
- +12
- Country India
Job Description
We are seeking an experienced Principal Software Engineer - Cybersecurity (VAPT) to lead Vulnerability Assessment and Penetration Testing (VAPT) activities across enterprise applications, cloud platforms, infrastructure, and IoT/OT environments. The ideal candidate will drive security testing strategies, identify vulnerabilities, recommend remediation measures, and mentor security engineers while working closely with development, DevOps, and infrastructure teams.
Key Responsibilities
- Lead and execute comprehensive Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, mobile applications, cloud environments, and network infrastructure.
- Perform manual and automated penetration testing to identify security weaknesses and validate exploitability.
- Conduct source code reviews and secure architecture assessments.
- Support secure software development lifecycle (SSDLC) initiatives and DevSecOps integration.
- Assess cloud security posture across AWS, Azure, and GCP environments.
- Perform cybersecurity risk assessments and provide mitigation recommendations.
- Validate remediation efforts through re-testing and security audits.
- Develop security standards, guidelines, and testing methodologies.
- Mentor and guide cybersecurity engineers and VAPT analysts.
- Collaborate with stakeholders to ensure compliance with industry standards such as ISO 27001, NIST, OWASP, IEC 62443, and GDPR.
Required Skills & Qualifications
- Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Security, or related field.
- 10+ years of experience in Cybersecurity, with at least 5 years focused on VAPT.
Strong expertise in:
- Web Application Security Testing
- API Security Testing
- Cloud Security Assessment
- Threat Modeling
Hands-on experience with tools such as:
- Burp Suite
- Nessus
- Nmap
- OWASP ZAP
- Wireshark
- Qualys
- Strong understanding of OWASP Top 10, CWE, CVSS, MITRE ATT&CK, and secure coding practices.
- Experience with CI/CD security integration and DevSecOps practices.
- Excellent analytical, problem-solving, and stakeholder management skills.