Job Description
About NopalCyber
NopalCyber makes cybersecurity manageable, affordable,reliable, and powerful for companies that need to be resilient and compliant.Through Managed Extended Detection and Response (MXDR), Attack SurfaceManagement (ASM), Breach and Attack Simulation (BAS), and Advisory Services, wefortify our clients’ cybersecurity across both offense and defence.
Our AI-driven Nopal360° platform, NopalGo mobile app,and proprietary Cyber Intelligence Quotient (CIQ) enable organizations toquantify, track, and visualize their cybersecurity posture in real time. Wedemocratize enterprise-grade security operations for organizations of all sizesby lowering the barrier to entry while raising the bar for security andservice.
Key Responsibilities
- Performadvanced Vulnerability Assessment and Penetration Testing (VAPT) acrossexternal infrastructure, internal networks, web and mobile applications,APIs, and cloud environments (AWS, Azure, GCP).
- ConductCIS Benchmark-based hardening assessments and implementations acrossoperating systems (Windows, Linux), databases, middleware, networkdevices, and cloud platforms.
- Delivercustomized hardening guides and security baselines mapped toclient-specific compliance requirements and regulatory frameworks.
- ExecuteDynamic Application Security Testing (DAST) on web and API applications(both authenticated and unauthenticated) using enterprise-grade tools;analyze, validate, and prioritize findings with actionable remediationguidance.
- RunBreach and Attack Simulation (BAS) scenarios to test resilience againstreal-world adversary tactics, techniques, and procedures (TTPs).
- Preparecomprehensive technical reports and executive-level summaries highlightingvulnerabilities, attack paths, misconfigurations, and compliance gaps.
- Continuouslyresearch emerging attack vectors, zero-day vulnerabilities, DASTmethodologies, and new CIS benchmark updates to refine assessmentstrategies.
- Contributeto Ransomware Resiliency Assessments (RRA) by simulating ransomwarebehaviors and evaluating control effectiveness.
Required Skills & Experience
- 8–12years of direct, hands-on cybersecurity consulting experience, with deepexpertise in VAPT, CIS benchmarking, and application security testing(DAST).
- Proventrack record performing end-to-end penetration tests and dynamicapplication security scans using industry tools such as Burp Suite Pro,OWASP ZAP, Nessus, Qualys, Netsparker, Acunetix, and custom scripts.
- Strongunderstanding of web application security flaws (OWASP Top 10, APIsecurity issues, authentication/authorization flaws, injection attacks,deserialization, SSRF, RCE, etc.) and ability to exploit and documentthem.
- Solidunderstanding of network protocols, operating system behaviors, and commonapplication security principles relevant to modern IT environments.
- Hands-onexperience with CIS Benchmark implementation and verification acrossdiverse platforms, ensuring alignment with client compliance mandates.
- Familiaritywith BAS tools and adversary emulation frameworks to measure detection andresponse maturity.
- Proficiencyin scripting/automation (Python, PowerShell, Bash) to extend testingcapabilities or validate findings.
- Workingknowledge of security architecture frameworks (e.g., SABSA) and threatmodeling methodologies (e.g., STRIDE, kill chains, attack trees) tosupport risk-informed vulnerability assessments, hardening efforts, andremediation planning.
- Abilityto write and present detailed remediation reports, securityrecommendations, and compliance-aligned hardening outputs.
- Strongcommunication skills to convey technical findings to technical andexecutive stakeholders.
Preferred Qualifications
- Bachelor’sdegree in engineering, Computer Science, or related discipline.
- CEHCertification (Mandatory) plus one or more advanced certifications:
- OSCP(Offensive Security Certified Professional)
- eCPPT(eLearn Security Certified Professional Penetration Tester)
- CRTP/ CRTE (Certified Red Team Professional/Expert)
- CIS-CATPro Assessor or equivalent CIS Benchmark credentials
- Familiaritywith MITRE ATT&CK and adversary simulation frameworks.
Preferred Qualifications
- Self-starter and quick learner requiring minimal ramp-up
- Excellent written, oral, and interpersonal communicationskills
- Highly self-motivated, self-directed, and attentive to detail
- Ability to effectively prioritize and execute tasks in ahigh-pressure environment
Location : Nopal Cyber, Hyderabad (Work from Office, 5 Days aWeek)