The Senior VAPT Engineer will be responsible for planning, leading, and executing vulnerability assessments and penetration testing engagements across web applications, mobile applications, APIs, networks, cloud environments, and infrastructure. The role requires conducting both automated and manual security assessments, identifying security vulnerabilities, validating risks through exploitation, and delivering comprehensive reports with practical remediation recommendations.
Key responsibilities include:
- Plan, scope, and execute VAPT engagements for web applications, mobile applications, APIs, internal and external networks, cloud infrastructure, and other technology environments.
- Work closely with clients to understand testing objectives, scope, business requirements, and engagement expectations.
- Perform manual and automated penetration testing to identify, validate, and exploit security vulnerabilities while assessing their business impact.
- Conduct vulnerability assessments using industry‑standard security tools and validate findings through manual verification to eliminate false positives.
- Perform security testing against recognized standards such as the OWASP Top 10, OWASP API Security Top 10, and other industry best practices.
- Analyze penetration testing results and prepare detailed technical reports, executive summaries, risk ratings, proof‑of‑concept evidence, and actionable remediation recommendations.
- Present technical findings, security risks, and mitigation strategies to clients and internal stakeholders.
- Collaborate with development, infrastructure, and security teams to support vulnerability remediation and perform retesting to validate fixes.
- Develop, maintain, and improve penetration testing methodologies, checklists, scripts, and automation tools to enhance testing efficiency.
- Stay current with emerging cyber‑threats, attack techniques, vulnerabilities, and security research to continuously improve assessment capabilities.
- Mentor and provide technical guidance to junior VAPT engineers and assist in knowledge sharing within the security team.
- Support pre‑sales activities, technical discussions, and client consultations when required.
Responsibilities
The Senior VAPT Engineer will lead end‑to‑end penetration testing engagements, ensuring compliance with organizational policies, client requirements, and industry security standards.
Requirements
Knowledge
- Strong knowledge of penetration testing methodologies and vulnerability assessment processes.
- In‑depth understanding of common security vulnerabilities, exploitation techniques, and remediation strategies.
- Solid understanding of network protocols, operating systems, web technologies, APIs, cloud environments, and security architecture.
- Familiarity with industry standards and frameworks including OWASP Top 10, OWASP API Security Top 10, NIST, ISO 27001, PCI‑DSS, and CIS Benchmarks.
- Knowledge of secure development practices and common attack vectors across modern applications.
Skills
- Hands‑on experience with penetration testing and vulnerability assessment tools including Nmap, Zmap, Burp Suite Professional, OWASP ZAP, SQLMap, Metasploit Framework, Nessus, OpenVAS, Wireshark, and related security tools.
- Experience performing manual web application, API, network, and infrastructure penetration testing.
- Strong analytical, troubleshooting, and problem‑solving skills.
- Excellent technical report writing and documentation skills.
- Strong verbal communication and presentation skills.
- Ability to develop scripts for automating security testing using Python, Bash, or PowerShell (advantage).
Abilities
- Lead penetration testing engagements independently from planning through reporting.
- Manage multiple projects while meeting deadlines.
- Mentor junior engineers and review technical deliverables.
- Maintain confidentiality and handle sensitive client information professionally.
- Work independently and collaboratively within cross‑functional teams.
Education, Experience, Licensure, Certification
- Bachelor's or Master's degree in Computer Science, Information Security, Cyber Security, or a related field.
- Minimum of 5 years of hands‑on experience in VAPT.
- Demonstrated experience conducting web application, API, network, and infrastructure penetration testing.
- Professional certifications such as OSCP, OSWE, OSEP, CRTO, CEH, PNPT, GPEN, eWPT, or equivalent are preferred.
- Experience with cloud security assessments (AWS, Azure, or GCP) is an advantage.
Competencies
- Vulnerability Assessment & Penetration Testing
- Web Application Security
- API Security Testing
- Network Penetration Testing
- Operating Systems (Windows/Linux)
- Networking Protocols
- Security Tools (Nmap, Burp Suite, OWASP ZAP)
- Security Frameworks (OWASP, NIST, ISO 27001, PCI‑DSS)
- Cloud Security Assessment
- Analytical Thinking
- Problem Solving
- Communication (Written & Verbal)
- Leadership & Mentoring
- Teamwork & Collaboration
- Client Management
- Reporting & Documentation
- Time Management
- Attention to Detail
- Continuous Learning
Benefits
- Excellent Salary
- Fuel Allowance
- Internet Allowance
- Medical Insurance
- Annual Leaves
- Provident Fund
- EOBI
- Annual Bonus