VAPT Security Engineer

ARC Document Solutions

Kolkata District

On-site

INR 1,500,000 - 2,700,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ARC Document Solutions is seeking a VAPT Security Engineer to join the Product Security team in Kolkata. You will identify and mitigate security risks across applications, infrastructure, and cloud environments, conducting in-depth security assessments and remediation.

You will work with Engineering, DevOps, and Product teams to strengthen security posture, perform both automated and manual testing, and deliver detailed reports with risk ratings and remediation guidance.

Qualifications

  • Bachelor's degree in Computer Science, IT, Cyber Security, or related field.
  • 3+ years of hands-on experience in VAPT or offensive security.
  • Strong analytical and problem-solving skills.
  • Excellent report writing and communication abilities.

Responsibilities

  • Perform VAPT on web apps, REST APIs, mobile apps, internal & external networks, and cloud infrastructure.
  • Conduct both automated and manual penetration testing using industry-standard methodologies.
  • Identify, exploit (where authorized), validate, and document security vulnerabilities.
  • Assess applications against OWASP Top 10, API Security Top 10, CWE, SANS Top 25.
  • Collaborate with developers and DevOps to remediate vulnerabilities and re-validate fixes.
  • Prepare detailed technical and executive-level VAPT reports with risk ratings and remediation guidance.

Skills

VAPT
Web security testing
API security testing
Network pentesting
Report writing

Education

Bachelor's degree in Computer Science/IT/Cyber Security

Tools

Burp Suite Pro
OWASP ZAP
Nessus
Nmap
Metasploit
SQLMap
Nikto
Wireshark
Gobuster
Dirsearch
Hydra
CrackMapExec

Job description

Job Title: VAPT Security Engineer

Location: Kolkata (Work from Office)
Experience: 3+ Years
Employment Type: Full-Time

About the Role

We are looking for a highly motivated VAPT Security Engineer to join our Product Security team. In this role, you will be responsible for identifying and mitigating security risks across our applications, infrastructure, cloud environments, and enterprise systems. You will work closely with Engineering, DevOps, and Product teams to strengthen our security posture by conducting in-depth security assessments, penetration testing, and vulnerability management.

If you are passionate about offensive security, ethical hacking, cloud security, and securing modern applications, we'd love to hear from you.

Key Responsibilities
  • Perform Vulnerability Assessment and Penetration Testing (VAPT) on:
    • Web Applications
    • REST APIs
    • Mobile Applications (Android/iOS)
    • Internal & External Networks
    • Cloud Infrastructure (AWS/Azure/GCP)
    • Containers and Kubernetes environments
  • Conduct both automated and manual penetration testing using industry-standard methodologies.
  • Identify, exploit (where authorized), validate, and document security vulnerabilities.
  • Assess applications against OWASP Top 10, API Security Top 10, CWE, SANS Top 25, and industry best practices.
  • Perform authenticated and unauthenticated security assessments.
  • Execute network, wireless, and infrastructure penetration testing.
  • Conduct source code reviews and secure code assessments where applicable.
  • Perform configuration reviews for servers, firewalls, cloud resources, and operating systems.
  • Collaborate with developers and DevOps engineers to remediate vulnerabilities and perform re-validation after fixes.
  • Prepare detailed technical and executive-level VAPT reports with risk ratings, business impact, proof of concept, and remediation guidance.
  • Track vulnerabilities from identification through closure.
  • Stay updated on emerging threats, CVEs, exploit techniques, zero-day vulnerabilities, and attack vectors.
Red Teaming Responsibilities (Preferred)
  • Participate in Red Team exercises and adversary simulations.
  • Conduct privilege escalation, lateral movement, and post-exploitation assessments in controlled environments.
  • Perform phishing simulations and security awareness testing.
  • Test detection capabilities of security monitoring solutions (EDR, SIEM, IDS/IPS).
  • Simulate real-world attack scenarios to evaluate organizational resilience.
Cloud Security Responsibilities
  • Assess cloud infrastructure security across AWS, Azure, or Google Cloud Platform.
  • Review IAM policies, security groups, network segmentation, storage configurations, and cloud-native security controls.
  • Perform security assessments for containers (Docker), Kubernetes clusters, and CI/CD pipelines.
  • Validate cloud compliance against security best practices.
Compliance & Governance

Experience supporting security assessments aligned with one or more of the following frameworks is desirable:

  • ISO 27001
  • SOC 2
  • PCI-DSS
  • NIST Cybersecurity Framework
  • CIS Benchmarks
  • GDPR
  • HIPAA (preferred)
Required Technical Skills
  • Strong hands-on experience in Vulnerability Assessment and Penetration Testing.
  • Expertise in:
    • Web Security Testing
    • API Security Testing
    • Network Penetration Testing
    • Infrastructure Security Assessment
  • Strong understanding of:
    • OWASP Top 10
    • OWASP API Security Top 10
    • MITRE ATT&CK Framework
    • CVSS
    • Common Vulnerabilities and Exposures (CVE)
Security Tools

Hands-on experience with multiple tools such as:

  • Burp Suite Professional
  • OWASP ZAP
  • Nessus
  • Nmap
  • Metasploit
  • SQLMap
  • Nikto
  • Wireshark
  • Acunetix
  • MobSF
  • Gobuster
  • Dirsearch
  • Hydra
  • BloodHound
  • Impacket
  • CrackMapExec (preferred)
Programming & Scripting

Good working knowledge of one or more of the following:

  • Python
  • Bash
  • PowerShell
  • JavaScript
  • SQL
Operating Systems

Hands-on experience with:

  • Linux
  • Windows Server
  • Active Directory
  • Networking Concepts
  • TCP/IP
  • DNS
  • HTTP/HTTPS
  • VPN
  • Firewalls
  • Reverse Proxies
Preferred Certifications

Candidates holding one or more of the following certifications will have an advantage:

  • OSCP
  • PNPT
  • CEH
  • eJPT
  • CompTIA Security+
  • CRTP
  • AWS Security Specialty
  • Azure Security Engineer Associate
Qualifications
  • Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related discipline.
  • 3+ years of hands-on experience in VAPT, penetration testing, or offensive security.
What We're Looking For
  • Strong analytical and problem-solving skills.
  • Passion for ethical hacking and offensive security.
  • Excellent report writing and communication skills.
  • Ability to work independently and collaboratively in a fast-paced product environment.
  • Continuous learner with a keen interest in emerging cyber threats and modern attack techniques.

If you're passionate about cybersecurity, enjoy solving complex security challenges, and want to make a meaningful impact by securing innovative products and cloud platforms, we'd love to hear from you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Assessment & Penetration Testing (VAPT) Engineer
Vulnerability Assessment & Penetration Testing (VAPT) Engineer

Zensar • Pune District

On-site
INR 1,200,000 - 2,800,000
VAPT Analyst
VAPT Analyst

Sveltetech Technologies • Gurugram District

On-site
INR 800,000 - 1,200,000
VAPT Engineer
VAPT Engineer

Ivalue Infosolutions • Bengaluru

On-site
INR 1,200,000 - 2,400,000
VAPT Lead
VAPT Lead

Adani Group • Ahmedabad District

On-site
INR 3,000,000 - 6,000,000
Cyber Security Specialist
Cyber Security Specialist

Muthoot FinCorp (MFL) • India

On-site
INR 1,200,000 - 2,400,000
Vapt Engineer
Vapt Engineer

Writer Corporation • Mumbai

On-site
INR 800,000 - 1,200,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Vapt Engineer
Vapt Engineer

Induct Hr Solutions • Thrissur

On-site
INR 1,100,000 - 1,800,000
Senior Security Testing Engineer
Senior Security Testing Engineer

Allied Boston Consultants India • Dadri

On-site
INR 900,000 - 1,300,000
VAPT Manager | Mumbai
VAPT Manager | Mumbai

ControlCase, LLC • Mumbai

Hybrid
INR 1,500,000 - 2,200,000