HamburgerMenu
hirist

Cyber Security Expert - Vulnerability Assessment & Penetration Testing

Next Gen Digital Technology
6 - 7 Years
Indore

Posted on: 26/06/2026

Job Description

Key Responsibilities:

Cyber Security Strategy & Governance:

- Develop, implement, and continuously improve the organization's cybersecurity framework, policies, standards, and procedures.

- Define enterprise security architecture aligned with business and regulatory requirements.

- Establish security governance models and ensure adherence across all IT environments.

- Conduct periodic security reviews and recommend improvements based on evolving cyber threats.

Security Risk Assessment & Audits:

- Perform comprehensive security risk assessments across applications, servers, databases, cloud platforms, and network infrastructure.

- Identify vulnerabilities, security gaps, and potential threats, and recommend mitigation strategies.

- Conduct IT security audits to ensure compliance with internal policies and industry standards.

- Prepare detailed risk assessment reports, audit findings, and remediation plans.

- Track closure of identified vulnerabilities and ensure timely implementation of corrective actions.

Vulnerability Assessment & Penetration Testing (VAPT):

- Plan, execute, and manage Vulnerability Assessment and Penetration Testing (VAPT) activities.

- Perform web application, network, API, wireless, and infrastructure security testing.

- Coordinate with external security auditors and penetration testing teams.

- Analyze VAPT findings, prioritize remediation based on risk, and validate fixes.

- Conduct periodic vulnerability scans and maintain vulnerability management dashboards.

Security Operations & Incident Response:

- Monitor enterprise security infrastructure for suspicious activities and security incidents.

- Investigate cyber threats, malware infections, unauthorized access attempts, and security breaches.

- Lead incident response activities including containment, eradication, recovery, and root cause analysis.

- Develop incident response playbooks and disaster recovery procedures.

- Maintain security logs and coordinate forensic investigations whenever required.

Network & Infrastructure Security:

- Secure enterprise LAN, WAN, cloud, wireless, and remote access infrastructure.

- Configure and manage firewalls, IDS/IPS, VPNs, Web Application Firewalls (WAF), endpoint protection, and email security solutions.

- Implement network segmentation, Zero Trust principles, and secure access controls.

- Ensure secure configuration of servers, operating systems, databases, and network devices.

Identity & Access Management:

- Implement strong authentication, authorization, and access control mechanisms.

- Manage Identity and Access Management (IAM), Multi-Factor Authentication (MFA), Privileged Access Management (PAM), and Single Sign-On (SSO).

- Conduct periodic user access reviews and privilege audits.

- Ensure compliance with least privilege and segregation of duties principles.

Security Compliance & Regulatory Management:

- Ensure compliance with cybersecurity standards, regulatory requirements, and organizational policies.

- Support internal and external security audits.

- Maintain security documentation, SOPs, compliance reports, and evidence for audits.

- Assist in achieving and maintaining relevant cybersecurity certifications where applicable.

Security Architecture & Solution Implementation:

- Evaluate, recommend, and deploy cybersecurity technologies and security controls.

- Design secure architectures for enterprise applications and infrastructure.

- Review security requirements during application development and system implementation.

- Collaborate with infrastructure, networking, cloud, and application teams to integrate security into all projects.

Cloud & Application Security:

- Implement security best practices across cloud environments.

- Perform cloud security assessments and configuration reviews.

- Conduct secure code reviews and application security testing.

- Ensure API security, encryption, certificate management, and secure data transmission.

Monitoring & Reporting:

- Develop cybersecurity dashboards and management reports.

- Track KPIs and KRIs related to vulnerabilities, incidents, compliance, and security posture.

- Present security findings and recommendations to senior leadership.

- Maintain asset inventories, risk registers, and security documentation.

Collaboration & Training:

- Work closely with IT infrastructure, development, networking, operations, and business teams to strengthen security controls.

- Conduct cybersecurity awareness sessions and phishing simulation exercises for employees.

- Provide technical guidance during new technology implementations and digital transformation initiatives.

- Mentor junior security professionals and support knowledge-sharing initiatives.

Required Skills:

- Strong knowledge of cybersecurity frameworks, security architecture, and enterprise security best practices.

- Hands-on experience in Vulnerability Assessment and Penetration Testing (VAPT).

- Experience in security audits, risk assessment, and risk mitigation.

- Strong understanding of network security, endpoint security, cloud security, application security, and database security.

- Experience with firewalls, IDS/IPS, VPNs, SIEM, endpoint detection and response (EDR), antivirus, and email security solutions.

- Knowledge of Identity and Access Management (IAM), Multi-Factor Authentication (MFA), and Privileged Access Management (PAM).

- Strong understanding of encryption technologies, PKI, SSL/TLS, and certificate management.

- Familiarity with operating systems including Windows and Linux.

- Experience in incident response, malware analysis, threat intelligence, and digital forensics.

- Understanding of secure software development lifecycle (SSDLC) and DevSecOps practices.

- Excellent analytical, troubleshooting, documentation, and communication skills.

Preferred Skills:

- Experience with Security Information and Event Management (SIEM) platforms.

- Exposure to cloud security platforms such as AWS, Microsoft Azure, or Google Cloud.

- Knowledge of container security, Kubernetes security, and DevSecOps.

- Experience in Operational Technology (OT), Industrial Control Systems (ICS), IoT, or Advanced Metering Infrastructure (AMI) security will be an added advantage.

- Familiarity with automation and scripting using PowerShell, Python, or Bash.

Educational Qualification:

- Bachelor's Degree (BE/B.Tech) in Computer Science, Information Technology, Computer Engineering, Electronics, or a related discipline from a recognized university.

Experience:

- 6-11 years of experience in Cyber Security, Information Security, or IT Security.

- Minimum 5 years of hands-on experience in cybersecurity implementation, security audits, risk assessment, VAPT, incident response, and enterprise security management.

- Experience in utility, power, manufacturing, smart grid, or AMI environments will be an added advantage.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...