VAPT Engineer

ATOMIT Corp.

Philippines

On-site

PHP 600,000 - 1,000,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ATOMIT Corp. is seeking a VAPT Engineer to identify and assess security vulnerabilities across web apps, mobile apps, APIs, networks, cloud, and infrastructure through comprehensive vulnerability assessments and penetration testing.

You will perform both manual and automated testing, identify weaknesses, and provide actionable remediation with detailed reporting. Collaboration with development and operations teams is essential to validate fixes and improve security posture.

Qualifications

  • At least 3 years of experience in vulnerability scanning, analysis, and penetration testing of websites, cloud-hosted apps, APIs, and networks.
  • Strong understanding of OWASP Top 10, network security, web app security, API security, authn/authz, and mobile security frameworks.
  • Hands-on experience with security tools: Burp Suite, Nmap, Metasploit, Nessus, Wireshark, OpenVAS.

Responsibilities

  • Perform VAPT on web/mobile apps, APIs, networks, and cloud environments.
  • Conduct manual and automated security testing.
  • Identify vulnerabilities and provide remediation recommendations.
  • Prepare detailed technical reports and executive summaries.
  • Collaborate with dev and infra teams to verify security fixes.
  • Perform security re-testing after remediation.
  • Stay updated on threats, techniques, and tools.
  • Support audits, compliance assessments, and security initiatives.

Skills

VAPT
Security testing
Burp Suite
Nmap
Metasploit
Nessus
Wireshark
OpenVAS
Python
Bash
PowerShell
Web API security
Mobile security

Tools

Burp Suite
Nmap
Metasploit
Nessus
Wireshark
OpenVAS

Job description

VAPT Engineer (Vulnerability Assessment & Penetration Testing)
About the Role

We are looking for a highly motivated and skilled VAPT Engineer to join our growing cybersecurity team. In this role, you will be responsible for identifying and assessing security vulnerabilities across web applications, mobile applications, APIs, networks, cloud environments, and infrastructure through comprehensive vulnerability assessments and penetration testing.

If you are passionate about ethical hacking, offensive security, and helping organizations strengthen their cybersecurity posture, we'd love to hear from you.

Key Responsibilities
  • Perform Vulnerability Assessment and Penetration Testing (VAPT) on web applications, mobile applications, APIs, internal and external networks, and cloud environments.

  • Conduct both manual and automated security testing.

  • Identify vulnerabilities, exploit weaknesses, and provide actionable remediation recommendations.

  • Prepare detailed technical reports and executive summaries.

  • Collaborate with development and infrastructure teams to validate and verify security fixes.

  • Perform security re-testing after remediation activities.

  • Stay updated with the latest cybersecurity threats, attack techniques, and security tools.

  • Support security audits, compliance assessments, and security-related initiatives as required.

Qualifications
Required Skills & Experience
  • At least 3 years of experience in vulnerability scanning, analysis, and penetration testing of websites, cloud-hosted applications, APIs, and networks.

  • Strong understanding of:

    • OWASP Top 10

    • Network security

    • Web application security

    • API security

    • Authentication and authorization mechanisms

    • Mobile security frameworks

  • Hands-on experience with security tools such as:

    • Burp Suite

    • Nmap

    • Metasploit

    • Nessus

    • Wireshark

    • OpenVAS

  • Knowledge of Linux and Windows environments.

  • Experience with scripting using Python, Bash, or PowerShell.

  • Understanding of secure coding principles.

  • Experience in manual penetration testing and exploit validation.

  • Strong technical documentation and reporting skills.

  • Knowledge of DevSecOps and integrating security into CI/CD pipelines.

  • Experience with application session management.

  • Good knowledge of modifying and compiling exploit code.

  • Exposure to ethical hacking programs such as Bug Bounty, Capture the Flag (CTF), or other security competitions.

Preferred Qualifications
  • One or more industry certifications, including:

    • OSCP

    • CEH

    • eJPT

    • GWAPT

    • CISSP

    • SANS

    • GXPN

  • Experience with:

    • Mobile application security testing

    • Cloud security

    • Red Team activities

    • Source code review

    • DevSecOps practices

Nice to Have
  • Experience in fintech, banking, or digital wallet applications.

  • Knowledge of secure SDLC and compliance frameworks.

  • Experience working in high-availability production environments with aggressive SLA requirements.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VAPT Engineer
VAPT Engineer

Hitachi Digital Payment Solutions Philippines Inc. • Philippines

On-site
PHP 800,000 - 1,500,000
Security Engineer - Offensive Security
Security Engineer - Offensive Security

Thrive • Tarlac City

On-site
PHP 900,000 - 1,500,000
VAPT Engineer: Offensive Security & App Security Testing
VAPT Engineer: Offensive Security & App Security Testing

ATOMIT Corp. • Philippines

On-site
PHP 600,000 - 1,000,000
Vulnerability and Penetration Tester
Vulnerability and Penetration Tester

Total Information Management Corp. • Philippines

On-site
PHP 600,000 - 1,000,000
Senior Pen Tester (Penetration Tester)
Senior Pen Tester (Penetration Tester)

Hammerjack Pty Ltd • Manila

On-site
PHP 154,000 - 271,000
Penetration Tester - Hybrid - BGC - up to 100K
Penetration Tester - Hybrid - BGC - up to 100K

weSource Management Consultancy Firm • Taguig

Hybrid
Security Engineer, Offensive Security
Security Engineer, Offensive Security

InfoHedge Technologies LLC • Morong

On-site
Senior Pen Tester
Senior Pen Tester

Hammerjack Pty Ltd • Manila

On-site
PHP 800,000 - 1,200,000
Penetration Tester - Up to 100K - Hybrid BGC - Midshift
Penetration Tester - Up to 100K - Hybrid BGC - Midshift

weSource Management Consultancy Firm • Metro Manila

Hybrid
PHP 80,000 - 100,000
Application Security Engineer
Application Security Engineer

Trinity Workforce Solutions, Inc. • Makati

On-site
PHP 800,000 - 1,200,000
Collaborate with talented teams
Work on real-world security challenges
Career growth in a security-first culture