Posted on: 04/09/2026
Role : Vulnerability Assessment & Penetration Tester (VAPT Engineer)
Department : Cyber Operations & Engineering
Location : Ahmedabad / Hybrid
Experience Required : 3 - 4 Years
Industry : Cybersecurity / MSSP / IT Services (Mandatory)
Role Summary :
The VAPT Engineer conducts technical assessments and offensive security testing across web applications, APIs, network infrastructure, and cloud environments. This role identifies security weaknesses, validates exploitability, eliminates false positives, and collaborates with engineering and infrastructure teams to ensure timely remediation and risk reduction.
Key Responsibilities :
- Offensive Security Assessments : Plan and execute black-box, gray-box, and white-box penetration tests across web applications, mobile apps, REST/GraphQL APIs, and internal/external network infrastructure.
- Vulnerability Management Lifecycle : Configure and run authenticated vulnerability scans, triage results to eliminate false positives, assign CVSS v3/v4 risk severity, and track findings through to closure.
- Manual Exploitation & PoCs : Supplement automated scans with manual testing techniques to identify complex business logic flaws, authorization bypasses, and chained attack vectors; create reproducible Proof of Concepts (PoCs).
- Remediation Support & Retesting : Provide actionable technical remediation guidance to DevOps, development, and network infrastructure teams; conduct re-assessments to validate effective patching.
- Reporting & Compliance : Author detailed technical reports with clear executive summaries, risk context, and remediation timelines aligned with compliance frameworks (ISO 27001, SOC 2, PCI-DSS).
- Threat Research : Track zero-days, emerging CVEs, and attack vectors, integrating new findings into existing vulnerability assessment routines.
Required Technical Skills & Qualifications :
- Experience : 3 - 4 years of dedicated hands-on experience performing vulnerability assessments and penetration testing within an enterprise or MSSP environment.
- Frameworks & Methodologies : Deep working knowledge of OWASP Top 10, SANS/CWE, PTES, CVSS, and MITRE ATT&CK.
- Tooling Proficiency : Advanced hands-on skills with Burp Suite Professional, Nessus, Qualys, Rapid7 InsightVM, Nmap, Metasploit, Wireshark, and Dirbuster/Gobuster.
- Environment Knowledge : Solid understanding of TCP/IP networking, Active Directory attack paths, web application architectures, and Linux/Windows OS hardening.
- Scripting : Working ability in Python, Bash, or PowerShell to customize exploit payloads and automate scan workflows.
- Soft Skills : Strong analytical capabilities, structured technical writing, and the ability to explain technical risk to non-technical stakeholders.
Preferred Certifications :
- OSCP (Offensive Security Certified Professional)
- PNPT (Practical Network Penetration Tester)
- eJPT / eWPT (eLearnSecurity Junior / Web Application Penetration Tester)
- CEH (Practical) or equivalent practical hands-on credential
Location : Ahemdabad, Gujarat
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1668600