Team Lead - ASR

NopalCyber

Hyderabad

On-site

INR 4,000,000 - 7,000,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

None

Job summary

NopalCyber is seeking a senior cybersecurity consultant to lead hands-on VAPT, CIS benchmarking, and security testing across diverse environments. You will craft remediation guidance, hardening baselines, and risk-focused assessments for client compliance and security posture.

Responsibilities include executing DAST/BAS scenarios, delivering technical reports, and staying ahead of emerging threats and CIS benchmarks while collaborating with client teams and executives.

Qualifications

  • 8–12 years of direct, hands-on cybersecurity consulting experience, with deep expertise in VAPT, CIS benchmarking, and app security testing.

Responsibilities

  • Perform advanced VAPT across external/internals, web/mobile apps, APIs, and cloud environments (AWS/Azure/GCP).
  • Conduct CIS benchmark hardening across OS, databases, middleware, and cloud platforms.
  • Deliver hardening guides and security baselines mapped to client compliance needs.
  • Execute DAST on web/API apps with authenticated and unauthenticated tests; provide remediation guidance.

Skills

VAPT
CIS Benchmark
Application Security
Python
PowerShell
Bash
Scripting
Threat Modelling
STRIDE
MITRE ATT&CK
Adversary Emulation
Communication

Education

Bachelor's degree

Tools

Burp Suite Pro
OWASP ZAP
Nessus
Qualys
Netsparker
Acunetix

Job description

Job Description
About NopalCyber

NopalCyber makes cybersecurity manageable, affordable,reliable, and powerful for companies that need to be resilient and compliant.Through Managed Extended Detection and Response (MXDR), Attack SurfaceManagement (ASM), Breach and Attack Simulation (BAS), and Advisory Services, wefortify our clients’ cybersecurity across both offense and defence.

Our AI-driven Nopal360° platform, NopalGo mobile app,and proprietary Cyber Intelligence Quotient (CIQ) enable organizations toquantify, track, and visualize their cybersecurity posture in real time. Wedemocratize enterprise-grade security operations for organizations of all sizesby lowering the barrier to entry while raising the bar for security andservice.

Key Responsibilities
  • Performadvanced Vulnerability Assessment and Penetration Testing (VAPT) acrossexternal infrastructure, internal networks, web and mobile applications,APIs, and cloud environments (AWS, Azure, GCP).
  • ConductCIS Benchmark-based hardening assessments and implementations acrossoperating systems (Windows, Linux), databases, middleware, networkdevices, and cloud platforms.
  • Delivercustomized hardening guides and security baselines mapped toclient-specific compliance requirements and regulatory frameworks.
  • ExecuteDynamic Application Security Testing (DAST) on web and API applications(both authenticated and unauthenticated) using enterprise-grade tools;analyze, validate, and prioritize findings with actionable remediationguidance.
  • RunBreach and Attack Simulation (BAS) scenarios to test resilience againstreal-world adversary tactics, techniques, and procedures (TTPs).
  • Preparecomprehensive technical reports and executive-level summaries highlightingvulnerabilities, attack paths, misconfigurations, and compliance gaps.
  • Continuouslyresearch emerging attack vectors, zero-day vulnerabilities, DASTmethodologies, and new CIS benchmark updates to refine assessmentstrategies.
  • Contributeto Ransomware Resiliency Assessments (RRA) by simulating ransomwarebehaviors and evaluating control effectiveness.
Required Skills & Experience
  • 8–12years of direct, hands-on cybersecurity consulting experience, with deepexpertise in VAPT, CIS benchmarking, and application security testing(DAST).
  • Proventrack record performing end-to-end penetration tests and dynamicapplication security scans using industry tools such as Burp Suite Pro,OWASP ZAP, Nessus, Qualys, Netsparker, Acunetix, and custom scripts.
  • Strongunderstanding of web application security flaws (OWASP Top 10, APIsecurity issues, authentication/authorization flaws, injection attacks,deserialization, SSRF, RCE, etc.) and ability to exploit and documentthem.
  • Solidunderstanding of network protocols, operating system behaviors, and commonapplication security principles relevant to modern IT environments.
  • Hands-onexperience with CIS Benchmark implementation and verification acrossdiverse platforms, ensuring alignment with client compliance mandates.
  • Familiaritywith BAS tools and adversary emulation frameworks to measure detection andresponse maturity.
  • Proficiencyin scripting/automation (Python, PowerShell, Bash) to extend testingcapabilities or validate findings.
  • Workingknowledge of security architecture frameworks (e.g., SABSA) and threatmodeling methodologies (e.g., STRIDE, kill chains, attack trees) tosupport risk-informed vulnerability assessments, hardening efforts, andremediation planning.
  • Abilityto write and present detailed remediation reports, securityrecommendations, and compliance-aligned hardening outputs.
  • Strongcommunication skills to convey technical findings to technical andexecutive stakeholders.
Preferred Qualifications
  • Bachelor’sdegree in engineering, Computer Science, or related discipline.
  • CEHCertification (Mandatory) plus one or more advanced certifications:
  • OSCP(Offensive Security Certified Professional)
  • eCPPT(eLearn Security Certified Professional Penetration Tester)
  • CRTP/ CRTE (Certified Red Team Professional/Expert)
  • CIS-CATPro Assessor or equivalent CIS Benchmark credentials
  • Familiaritywith MITRE ATT&CK and adversary simulation frameworks.
Preferred Qualifications
  • Self-starter and quick learner requiring minimal ramp-up
  • Excellent written, oral, and interpersonal communicationskills
  • Highly self-motivated, self-directed, and attentive to detail
  • Ability to effectively prioritize and execute tasks in ahigh-pressure environment

Location : Nopal Cyber, Hyderabad (Work from Office, 5 Days aWeek)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Specialist
Cyber Security Specialist

Muthoot FinCorp (MFL) • Thiruvananthapuram

On-site
INR 900,000 - 1,300,000
Senior Penetration Tester
Senior Penetration Tester

ESDS Software Solution Limited • Nashik District

On-site
INR 2,500,000 - 4,200,000
Red Teaming - Manager
Red Teaming - Manager

Deloitte Development LLC • Bengaluru

On-site
INR 2,800,000 - 4,500,000
Cybersecurity Solutions Consultant
Cybersecurity Solutions Consultant

NopalCyber • Hyderabad

On-site
INR 2,500,000 - 4,000,000
VAPT Manager | Mumbai
VAPT Manager | Mumbai

ControlCase, LLC • Mumbai

Hybrid
INR 1,500,000 - 2,200,000
Penetration Testing Senior Consultant
Penetration Testing Senior Consultant

Alignity Solutions • Hyderabad

Hybrid
INR 1,800,000 - 3,000,000
Hybrid work
Senior Penetration Tester
Senior Penetration Tester

Tsaaro Consulting Inc. • Bengaluru

Hybrid
INR 2,000,000 - 3,200,000
Technical Lead-Cybersecurity
Technical Lead-Cybersecurity

Birlasoft • Dadri

On-site
INR 1,200,000 - 2,400,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Cyderes • India

On-site
INR 1,200,000 - 2,400,000
Senior Security Testing Engineer
Senior Security Testing Engineer

Allied Boston Consultants India • Dadri

On-site
INR 900,000 - 1,300,000