Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
Adani Enterprises Ltd seeks a seasoned VAPT Lead to drive vulnerability assessments across our infrastructure, applications, and networks, shaping security strategy and fostering incident readiness. You will mentor a security team, coordinate with IT and development groups, perform risk-based testing, and deliver actionable remediation guidance to senior leadership.
A strong background in OSCP/CEH/CISSP and scripting is required, with hands-on experience using Nessus, Burp Suite, Metasploit, and
VAPT Lead About Business: Adani Group: In recent years, we have evolved from a new player in power generation to India’s largest private thermal power producer, with a capacity of 15,250 MW and a 40 MW solar project in Gujarat. It has created a world-class logistics and utility infrastructure portfolio that has a pan-India presence. Adani Group is headquartered in Ahmedabad, in the state of Gujarat, India. Over the years, Adani Group has positioned itself to be the market leader in its logistics and energy businesses focusing on large-scale infrastructure development in India with O & M practices benchmarked to global standards. With four IG-rated businesses, it is the only Infrastructure Investment Grade issuer in India.
The VAPT Lead will be responsible for leading the vulnerability assessment and penetration testing (VAPT) initiatives across the organization. This role involves managing the entire VAPT process, from planning and scoping assessments to executing and reporting on findings. The VAPT Lead will collaborate with other cybersecurity teams to identify, assess, and mitigate vulnerabilities in the organization’s infrastructure, applications, and network environments. The VAPT Lead is a key player in improving the security posture of the organization by providing in-depth security testing and actionable insights to prevent potential cyber threats.
Lead and manage comprehensive VAPT activities across the organization’s infrastructure, applications, and network systems. Plan and scope penetration tests and vulnerability assessments based on organizational needs and potential risks. Perform vulnerability scanning, manual testing, and exploitations of identified vulnerabilities. Conduct internal and external penetration testing to identify potential weaknesses in systems, applications, and networks. Perform risk assessments and prioritize remediation based on business impact and severity.
Lead and mentor a team of security professionals, including penetration testers and vulnerability assessors. Allocate resources effectively for different VAPT projects and ensure timely execution of testing activities. Provide coaching, guidance, and training to junior team members to foster a growth environment and enhance skill sets. Ensure adherence to best practices, policies, and ethical standards while conducting penetration testing.
Work closely with security operations, incident response, and other teams to share findings and ensure alignment between security testing and overall security strategy. Provide security recommendations for remediation based on findings from VAPT assessments and assist with the implementation of mitigation strategies. Collaborate with development teams, IT, and system administrators to support vulnerability remediation efforts.
Prepare comprehensive reports on VAPT findings, including vulnerabilities discovered, risk assessments, exploitability, and recommended remediations. Provide both high-level executive summaries and detailed technical reports for different stakeholders (management, technical teams, etc.). Track the progress of vulnerabilities remediation and provide regular updates to senior leadership.
Ensure that penetration testing and vulnerability assessments follow relevant security frameworks, industry standards, and compliance regulations (e.g., OWASP, NIST, ISO 27001, GDPR). Perform regular assessments of compliance requirements and security controls to ensure adherence to security policies. Contribute to the development of organizational policies and guidelines related to vulnerability management, penetration testing, and overall security best practices.
Lead the selection, deployment, and management of security tools and technologies used for vulnerability assessments, penetration testing, and exploit research (e.g., Nessus, Burp Suite, Metasploit, Nmap, etc.). Continuously evaluate and improve the use of security tools to enhance testing capabilities and ensure efficiency.
Stay up-to-date with the latest cybersecurity threats, attack methods, vulnerabilities, and industry trends. Conduct research to identify emerging security threats and testing techniques and incorporate them into testing methodologies. Maintain knowledge of advanced attack techniques and tools to simulate real-world attacks and improve testing accuracy.
Continuously improve testing methodologies, processes, and workflows to increase the effectiveness of VAPT efforts. Develop and implement new strategies for proactive vulnerability management and penetration testing based on lessons learned and evolving threats. Advocate for continuous improvement of the organization’s overall security posture based on VAPT findings and industry best practices.
Support the incident response team in analyzing vulnerabilities related to security incidents, providing insights into the potential exploitation of discovered vulnerabilities. Assist in the development of incident response plans, particularly in relation to vulnerability management and exploitation scenarios.
Chief Information Security Officer (CISO), Business Unit Heads and Department Heads, Information Security and IT teams, Risk Management Teams, Security Operations Team, Engineering & Development Teams, Incident Response Teams
Regulatory Authorities, Third-Party Service Providers, Educational Institutions
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. Advanced degree (e.g., Master's, MBA) in Cybersecurity, Information Assurance, or a relevant discipline is highly desirable.
Relevant certifications such as Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), or GIAC Penetration Tester (GPEN) are highly preferred. Extensive experience with vulnerability scanning tools (e.g., Nessus, OpenVAS), web application testing tools (e.g., Burp Suite), and penetration testing frameworks. Deep knowledge of common web and network vulnerabilities (e.g., SQL injection, XSS, buffer overflows, etc.) and security tools. Experience with scripting and automation (e.g., Python, Bash, PowerShell) is a plus.
5+ years of hands‑on experience in penetration testing, vulnerability assessment, and ethical hacking. Experience Level Senior Level