VAPT Analyst

Cybersmithsecure

Mumbai

On-site

INR 600,000 - 900,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cybersmithsecure is seeking a VAPT Analyst to perform hands-on vulnerability assessment and penetration testing across web, mobile, cloud, and network environments. The role emphasizes technical execution, exploitability validation, and remediation guidance within a security-focused team.

You will contribute to red team and purple team initiatives, produce detailed reports, and help strengthen detection capabilities while operating in an internship-to-fulltime pathway.

Qualifications

  • Hands-on VAPT experience across web, API, mobile, and network domains.
  • Ability to perform manual exploitation and validate findings.
  • Familiarity with MITRE ATT&CK and risk-based reporting.

Responsibilities

  • Perform web app, API, and mobile security testing with manual validation.
  • Assess internal networks, AD/AAD, and cloud environments for misconfigurations.
  • Conduct red team support and contribute to purple team activities.
  • Prepare client-ready VAPT reports with risk ratings and remediation steps.
  • Validate findings through retesting and evidence collection.

Skills

Web app pentesting
API security testing
Mobile app security
Internal network pentesting
Cloud security testing

Tools

Burp Suite
Nmap
Nuclei
Metasploit
CrackMapExec
BloodHound

Job description

Job Description: VAPT Analyst
Job Title

VAPT Analyst (Vulnerability Assessment & Penetration Testing)

Employment Type

Intern / Trainee / FullTime

Department

Cyber Security and VAPT

Role Overview

The VAPT Analyst is responsible for conducting hands-on vulnerability assessment and penetration testing across applications, infrastructure, identity systems, cloud environments, and networks. This is a technical execution-focused role requiring real exploitation capability, attack simulation, and validation of security controls rather than reliance on automated scanning alone. The role also supports red teaming and purple teaming initiatives, helping improve both offensive depth and defensive detection capabilities. Findings produced by this role directly influence risk posture, remediation priorities, and audit readiness.

Key Responsibilities
1. Web Application Security Testing
  • Conduct black-box, gray-box, and authenticated penetration testing on web applications, portals, dashboards, and administrative interfaces.
  • Identify and exploit vulnerabilities including:
    • Broken authentication and authorization (IDOR, privilege escalation, access control bypass)
    • Injection vulnerabilities (SQLi, command injection, SSTI, XXE)
    • Session management flaws (JWT issues, CSRF, token misuse, session fixation)
  • Test complex business logic flows such as workflows, approvals, role-based actions, and transaction handling.
  • Manually validate findings to eliminate false positives and assess real-world exploitability.
2. Application & API Security Testing
  • Perform security testing of backend applications and APIs (REST, GraphQL, internal services).
  • Assess API authentication, authorization, rate limiting, object-level access control, and data exposure risks.
  • Test for insecure deserialization, mass assignment, improper input validation, and logic flaws.
  • Evaluate application error handling, logging behavior, and trust boundaries.
3. Mobile Application Security (Android & iOS)
  • Conduct static and dynamic analysis of Android and iOS applications.
  • Assess security of API communication, SSL pinning, token storage, and local data handling.
  • Test root/jailbreak detection mechanisms and bypass techniques.
  • Identify insecure permissions, intents, deep links, and client-side logic flaws.
4. Infrastructure & Internal Network Penetration Testing
  • Perform penetration testing of internal networks, servers, and remote access infrastructure.
  • Identify weak authentication mechanisms, exposed services, misconfigurations, and lateral movement paths.
  • Simulate internal attacker scenarios to assess impact of compromised credentials or endpoints.
5. Active Directory & Identity Security Testing
  • Conduct security testing of Active Directory and Azure AD environments.
  • Assess identity misconfigurations and excessive privileges that could lead to domain compromise.
6. Cloud Security Testing
  • Perform security testing of cloud environments (AWS / Azure / GCP).
  • Identify misconfigurations related to IAM, storage exposure, logging, monitoring, and network controls.
  • Assess cloud-specific attack vectors including metadata abuse and over-permissive roles.
7. Network, Firewall & Device Security Testing
  • Test firewalls, VPNs, network segmentation, and exposed management interfaces.
  • Identify weak ACLs, insecure rule configurations, and unnecessary exposure of services.
  • Validate effectiveness of network security controls through controlled exploitation.
8. Red Teaming & Purple Teaming Support
  • Participate in red team exercises simulating real-world adversary behavior across multiple attack stages.
  • Support purple teaming activities by collaborating with detection and SOC teams to improve visibility.
  • Help develop attack playbooks, detection use cases, and post-exercise improvement recommendations.
9. Vulnerability Validation, Reporting & Retesting
  • Validate scanner findings and eliminate false positives through manual testing.
  • Prepare detailed VAPT reports including:
    • Risk-based severity ratings
    • Exploitation steps and evidence
    • Business impact explanation
    • Remediation guidance mapped to best practices
  • Perform retesting to confirm effective remediation and closure.
Required Skills & Qualifications
Offensive Security & Testing Skills
  • Strong hands-on experience in:
    • Web application and API penetration testing
    • Mobile application security (Android & iOS)
    • Internal network and infrastructure pentesting
    • Active Directory and identity security testing
    • Cloud security testing (AWS / Azure / GCP)
Red Teaming & Purple Teaming
  • Understanding of red teaming methodologies, attack chains, and adversary simulation.
  • Experience supporting purple team engagements, including detection validation and feedback.
  • Familiarity with MITRE ATT&CK framework and mapping techniques.
Frameworks & Standards
  • OWASP Top 10 (Web, API, Mobile)
  • OWASP ASVS (preferred)
  • Common Weakness Enumeration (CWE)
Platforms & Tools
  • Tools: Burp Suite, Nmap, Nuclei, Metasploit, CrackMapExec, BloodHound
  • Mobile tools: MobSF, Frida, JADX, APKTool
  • Environments: Windows, Linux, Active Directory, Azure AD
  • Cloud platforms: AWS / Azure / GCP
Certifications
  • CEH
  • OSCP, OSWE, CRTP, CRTO, or equivalent offensive security certifications
Experience Levels (Flexible)
VAPT Intern (0-1 Years)
  • Supports VAPT engagements by executing test cases, running tools, and identifying common vulnerabilities.
  • Learns manual exploitation techniques and basic attack paths under supervision.
  • Assists in report preparation, evidence capture, and vulnerability retesting.
VAPT Analyst (1-4 Years)
  • Independently executes end-to-end VAPT engagements across web, API, infrastructure, and cloud scopes.
  • Performs manual exploitation, attack chaining, and business impact assessment.
  • Produces high-quality, client-ready reports and supports remediation discussions.
Senior VAPT Analyst (4+ Years)
  • Leads complex VAPT, red team, and purple team engagements involving multiple attack vectors.
  • Designs advanced attack paths and mentors junior analysts.
  • Reviews reports for technical accuracy, risk justification, and audit defensibility.
What Success Looks Like
  • Vulnerabilities are accurately identified, validated, and risk-rated
  • Critical and high-risk issues are clearly exploitable and reproducible
  • Remediation efforts result in verified, sustainable fixes
  • Attack surface and repeat findings reduce measurably over time
Why Join Us
  • Opportunity to design core operational systems
  • High ownership and visibility
  • Flexibility in experience level
  • Handson exposure to real project workflows and automation
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VAPT Lead
VAPT Lead

Adani Group • Ahmedabad District

On-site
INR 3,000,000 - 6,000,000
Vulnerability Assessment and Penetration Testing Lead
Vulnerability Assessment and Penetration Testing Lead

adani capital pvt ltd • Ahmedabad District

On-site
INR 2,500,000 - 4,200,000
VAPT Analyst
VAPT Analyst

Sveltetech Technologies • Gurugram District

On-site
INR 800,000 - 1,200,000
VAPT Manager | Mumbai
VAPT Manager | Mumbai

ControlCase, LLC • Mumbai

Hybrid
INR 1,500,000 - 2,200,000
Security Analyst - VAPT
Security Analyst - VAPT

TechDefence Labs • Delhi

On-site
INR 700,000 - 1,000,000
Competitive salary and benefits package
Opportunities for continuous learning
Vulnerability Assessment and Penetration Testing Lead
Vulnerability Assessment and Penetration Testing Lead

Adani Enterprises Ltd • Ahmedabad District

On-site
INR 2,500,000 - 4,000,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Jobtailor • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Penetration Tester
Penetration Tester

Soffit Infrastructure Services (P) Ltd • Ernakulam

On-site
INR 1,200,000 - 2,200,000
Senior VAPT Consultant
Senior VAPT Consultant

Thinkaloud Consulting • Shillong

On-site
INR 800,000 - 1,600,000
Security Tester
Security Tester

Paramount Computer Systems LLC • Coimbatore District

On-site
INR 900,000 - 1,300,000