HamburgerMenu
hirist

Senior VAPT Consultant

Thinkaloud Consulting Private Limited
12 - 15 Years
Shillong

Posted on: 24/07/2026

Job Description

We are seeking an experienced Senior VAPT Consultant to lead enterprise-level Vulnerability Assessment and Penetration Testing (VAPT) engagements across web applications, APIs, mobile applications, cloud environments, and enterprise infrastructure. This role is responsible for identifying security vulnerabilities, assessing cyber risks, driving remediation efforts, and strengthening the organization's overall security posture.

The ideal candidate will have extensive experience in offensive security, application security, secure code review, and regulatory compliance, along with the ability to mentor security teams and engage with senior stakeholders on cybersecurity initiatives.

Key Responsibilities:

- Lead end-to-end Vulnerability Assessment and Penetration Testing (VAPT) engagements across web applications, mobile applications, APIs, cloud environments, and enterprise infrastructure.

- Plan, execute, and manage penetration testing activities for internal and external applications, networks, databases, servers, firewalls, endpoints, and cloud platforms.

- Perform advanced manual penetration testing to identify complex vulnerabilities that may not be detected through automated tools.

- Conduct authenticated and unauthenticated security assessments using industry-standard methodologies and tools.

- Assess applications against the latest OWASP Top 10, OWASP API Security Top 10, SANS Top 25, and other industry-recognized security standards.

- Perform API security testing for REST, SOAP, GraphQL, OAuth, JWT, and microservices-based architectures.

- Conduct mobile application security assessments for Android and iOS platforms, identifying weaknesses in authentication, data storage, encryption, and communication.

- Perform infrastructure and network security assessments covering Windows, Linux, Active Directory, databases, firewalls, VPNs, wireless networks, and cloud services.

- Lead secure source code reviews to identify insecure coding practices, security flaws, and architectural weaknesses.

- Analyze vulnerabilities, assign CVSS scores, determine business impact, and prioritize remediation based on risk.

- Prepare detailed VAPT reports including executive summaries, technical findings, proof of concept, screenshots, exploit evidence, and actionable remediation recommendations.

- Validate remediation efforts by conducting re-testing and issuing vulnerability closure reports.

- Review and validate third-party penetration testing reports and ensure findings meet organizational security standards.

- Provide technical guidance to development, DevOps, infrastructure, and architecture teams on secure design principles and vulnerability remediation.

- Support implementation of Secure SDLC and DevSecOps practices across application development lifecycles.

- Participate in threat modeling, security architecture reviews, and application security assessments during project design phases.

- Align security testing activities with ISO 27001, RBI Cyber Security Framework, PCI DSS, NIST, CIS Controls, and other regulatory requirements.

- Support internal and external security audits, regulatory assessments, and compliance reviews.

- Develop, maintain, and enhance penetration testing methodologies, testing playbooks, and security assessment frameworks.

- Mentor junior VAPT consultants by reviewing assessment reports, providing technical guidance, and promoting best practices.

- Stay updated on emerging cyber threats, exploit techniques, zero-day vulnerabilities, and evolving attack vectors.

- Collaborate with Security Operations, Incident Response, Infrastructure, Cloud, and Product Engineering teams to improve the organization's security maturity.

Experience:

- 10-15 years of experience in Application Security, VAPT, Penetration Testing, or Offensive Security.

- Proven experience leading enterprise VAPT engagements across web, mobile, API, network, and cloud environments.

- Strong background in secure code review and security architecture assessments.

- Experience in Banking, Financial Services, FinTech, or other highly regulated industries is highly preferred.

- Hands-on experience with compliance frameworks such as ISO 27001, PCI DSS, and RBI cybersecurity guidelines.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...