VAPT Security Engineer

Zohorecruit

Hyderabad

Hybrid

INR 1,800,000 - 2,800,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Zohorecruit is seeking a Penetration Testing Senior Consultant in a hybrid setup for long-term engagements in India. You will lead offensive security engagements across apps, APIs, mobile, cloud, and enterprise infra, translating findings into actionable risk and remediation recommendations.

The role demands 7+ years of hands-on cybersecurity experience, deep OWASP knowledge, and strong reporting skills. Responsibilities include designing test plans, performing manual and automated assessments,

Qualifications

  • 7+ years of hands-on cybersecurity experience in penetration testing or related security roles.
  • Experience across web, APIs, mobile, thick-client, networks, cloud, and enterprise infra.
  • Strong knowledge of OWASP Top 10 and practical vulnerability exploitation.
  • Hands-on with manual testing plus automated tooling for efficient assessments.
  • Proficiency with Burp Suite and a suite of security testing tools.
  • Experience with secure code reviews and threat modeling.
  • Ability to translate findings into business risk and remediation plans.

Responsibilities

  • Lead penetration testing workstreams across web, APIs, mobile, and cloud environments.
  • Design test plans and perform manual and automated security assessments.
  • Identify, validate, exploit, and document vulnerabilities with remediation guidance.
  • Conduct secure code reviews and threat modeling.
  • Prepare detailed reports and executive summaries for clients.
  • Mentor junior team members and support engagement planning.

Skills

Penetration testing
OWASP Top 10
Manual testing
Automated security testing
Burp Suite
Nmap
Metasploit
Python
PowerShell
Threat modeling
OAuth 2.0
OpenID Connect
Security reporting
Reverse engineering basics
Documentation
Team mentoring

Tools

Burp Suite
Fiddler
Wireshark
Nmap
Metasploit
Nessus
Qualys
Tenable
Veracode
Frida
Apktool
JADX
dnSpy
IDA Pro

Job description

Do you love a career where you Experience , Grow & Contribute at the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you.

Learn how we are redefining the meaning of work , and be a part of the team raved by Clients, Job-seekers and Employees.

If you are a Penetration Testing Senior Consultant looking for excitement, challenge and stability in your work, then you would be glad to come across this page.

We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.

Check if you are up for maximizing your earning/growth potential, leveraging our Disruptive Talent Solution.

Role: Penetration Testing Senior Consultant

Work Mode: Hybrid

Type: Contract to Hire

Notice Period:Immediate Joiners

Requirements

As a Penetration Testing Senior Consultant , you will lead the execution of offensive security engagements and help clients identify, validate, and remediate security vulnerabilities across their digital ecosystem.

You will work across application, API, mobile, thick-client, network, cloud, and enterprise infrastructure environments while collaborating with technical and business stakeholders to translate security findings into actionable business risk and remediation recommendations.


Key Responsibilities
  • Lead penetration testing workstreams across web applications, APIs, mobile, thick-client, network, cloud, and infrastructure environments .
  • Design test plans and execute manual and automated security assessments .
  • Identify, validate, exploit, and document security vulnerabilities.
  • Perform manual testing for vulnerabilities including:
    • SQL Injection / Blind SQL Injection
    • XSS and CSRF
    • XXE
    • SSRF
    • Insecure Deserialization
    • HTTP Request Smuggling
    • Authentication & Authorization weaknesses
    • Business Logic vulnerabilities
  • Assess OAuth 2.0, OpenID Connect, session management, identity, and access controls .
  • Conduct secure code reviews using OWASP Secure Coding Practices or comparable methodologies.
  • Perform application security architecture reviews and threat modeling .
  • Conduct vulnerability assessments across application, infrastructure, cloud, mobile, and enterprise environments.
  • Use industry-standard security testing tools such as Burp Suite, Fiddler, Wireshark, Nmap, Metasploit, Nessus, Qualys, Tenable, Veracode, Frida, Apktool, JADX, dnSpy, and IDA Pro .
  • Develop scripts and automation using Python, PowerShell, Bash, or similar technologies to improve reconnaissance, testing, evidence collection, and reporting.
  • Support purple team, red team, adversarial simulation, and threat-informed testing activities.
  • Map attack scenarios and findings to MITRE ATT&CK and relevant threat behaviors.
  • Coordinate with application, infrastructure, cloud, development, and security operations teams for remediation and retesting.
  • Prepare detailed technical reports, executive summaries, risk-based findings, remediation recommendations, and client presentations.
  • Translate technical vulnerabilities into business-relevant risk statements and prioritized remediation plans.
  • Support engagement planning, estimation, proposal development, solution development, and identification of follow-on opportunities.
  • Mentor junior team members and review technical deliverables.
  • Provide technical and professional feedback to team members.
  • Prepare daily, weekly, quarterly, and annual status reports and remediation tracking materials.
  • Respond to ad-hoc research, reporting, and technical requests from management and clients.
  • Adhere to internal security requirements and Deloitte policies.
Must-Have Skills & Experience
  • 7+ years of hands-on cybersecurity experience in penetration testing, application security, cyber risk, vulnerability assessment, or related technical security roles.
  • Proven experience conducting penetration testing across multiple domains:
    • Web Applications
    • APIs
    • Mobile Applications
    • Thick-Client Applications
    • Networks
    • Cloud
    • Enterprise Infrastructure
  • Strong knowledge of OWASP Top 10 and application security vulnerabilities.
  • Strong hands-on experience with manual vulnerability assessment and exploitation.
  • Strong understanding of:
    • OAuth 2.0
    • OpenID Connect
    • Identity Management
    • Session Management
    • Access Control
  • Experience with secure code reviews .
  • Strong hands-on experience with manual penetration testing combined with automated security tools.
Proficiency with tools such as:

Burp Suite, Fiddler, Wireshark, Nmap, Metasploit, Nessus, Qualys, Tenable, Veracode, Frida, Apktool, JADX, dnSpy, IDA Pro or equivalent.

  • Strong understanding of web application architecture, including frontend, backend, databases, APIs, application servers, and middleware .
  • Experience with application security architecture assessment and threat modeling.
  • Understanding of basic reverse engineering and memory analysis concepts.
  • Strong understanding of networking protocols including TCP/IP, DNS, HTTP/HTTPS, SMB, and LDAP .
  • Familiarity with CVE and CVSS .
  • Excellent technical documentation and report-writing skills.
  • Strong analytical, problem-solving, prioritization, and stakeholder-management skills.
At least one relevant cybersecurity certification such as:

OSCP, OSWP, GPEN, GWAPT, BSCP, OSWE, CISSP, or CREST certification.

Good-to-Have Skills
  • Application, infrastructure, cloud, mobile, and microservices security assessment experience.
  • Experience testing AI-enabled applications, LLM integrations, APIs, AI agents, or related systems .
  • Red Team, Purple Team, breach attack simulation, or adversary emulation experience.
  • Knowledge of:
    • MITRE ATT&CK
    • Cyber Kill Chain
    • SANS Top 25
    • Threat-informed penetration testing
  • Experience with offensive security tools such as Cobalt Strike, Sliver, BloodHound, Empire, Metasploit, Nmap, Qualys, and Tenable .
  • Knowledge of Active Directory security, privilege escalation, lateral movement, identity attacks, and enterprise misconfigurations .
  • Experience assessing AWS, Azure, or GCP environments, including IAM, storage, compute, networking, containers, and Kubernetes.
  • Familiarity with security monitoring platforms such as Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, Splunk, QRadar, and ArcSight .
  • Working knowledge of malware analysis, reverse engineering, binary analysis, exploit development, or memory analysis .
  • Security automation and scripting experience using Python, PowerShell, Bash, or similar languages .
  • Ability to translate threat intelligence into realistic and controlled attack scenarios.
  • Experience presenting security findings to both technical and executive audiences.
  • Security research, publications, blogs, open-source projects, conference presentations, or CVEs.
  • Preferred certifications: OSWE, OSEP, OSED, OSCE3, CRTO, GXPN, OSEE, AWS Security Specialty, SABSA, or CREST offensive security certifications .
  • Familiarity with NIST, PCI DSS, HIPAA, GDPR , and other relevant cybersecurity/privacy standards.
  • Strong written and verbal English communication skills.
  • Strong interest in continuous learning and developing new offensive security techniques.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Penetration Testing Senior Consultant
Penetration Testing Senior Consultant

Alignity Solutions • Hyderabad

Hybrid
INR 1,800,000 - 3,000,000
Hybrid work
Cyber Penetration Tester
Cyber Penetration Tester

Alignity Solutions • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Senior Security Consultant
Senior Security Consultant

Wattlecorp Cybersecurity Labs LLP • Kozhikode district

On-site
INR 1,800,000 - 3,000,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Jobtailor • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Penetration Tester
Penetration Tester

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
SAST/DAST Application Security Consultant (Pen Testing)
SAST/DAST Application Security Consultant (Pen Testing)

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Security Engineer - OSCP
Security Engineer - OSCP

TAC Security • Delhi

On-site
INR 1,200,000 - 1,800,000
Network Security
Network Security

Sisainfosec • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Application Security Consultant
Application Security Consultant

SecurityBoat Cybersecurity Solutions Private Limited • Mumbai

On-site
INR 1,200,000 - 2,200,000
Competitive compensation
Specialized cybersecurity team
Professional development
Senior Security Consultant
Senior Security Consultant

Payatu Technologies Pvt Ltd • Pune District

On-site
INR 1,800,000 - 3,200,000