We are seeking a skilled cybersecurity professional with 2 to 5 years of experience specializing in Vulnerability Assessment and Penetration Testing (VAPT), application security, or related fields. The ideal candidate will have hands-on expertise in identifying and mitigating security risks, particularly those outlined in the OWASP Top 10 and API security vulnerabilities. This role requires a strong technical foundation combined with excellent communication skills to effectively convey findings to both technical and non-technical stakeholders.
Key Responsibilities
- Plan and execute authorized VAPT engagements across web applications, APIs, mobile platforms, and infrastructure environments.
- Assess critical security aspects such as authentication, authorization, session management, input validation, and common application vulnerabilities.
- Perform thorough API security testing and review security controls for various platform integrations.
- Support security testing efforts for mobile applications on both iOS and Android operating systems.
- Evaluate cloud and infrastructure configurations, with a focus on AWS and related environments.
- Document findings clearly, detailing severity levels, business impact, supporting evidence, and actionable remediation guidance.
- Collaborate closely with engineering, DevOps, QA, and product teams to facilitate timely remediation of identified vulnerabilities.
- Conduct retesting to validate that vulnerabilities have been effectively resolved.
- Promote secure Software Development Life Cycle (SDLC) practices, contribute to security awareness initiatives, and assist in vulnerability management reporting.
Required Qualifications
- 2 to 5 years of practical experience in VAPT, application security, cybersecurity, or a closely related discipline.
- Solid understanding of the OWASP Top 10 security risks and API security challenges.
- Hands-on experience with security testing tools such as Burp Suite, Nmap, Nessus, OWASP ZAP, or their equivalents.
- Strong knowledge of Linux systems, networking fundamentals, HTTP protocols, authentication mechanisms, and common security controls.
- Excellent reporting, documentation, and communication skills, capable of articulating technical findings clearly to diverse audiences.
- Relevant industry certifications such as OSCP, CEH, eJPT, Security+, or equivalents.
- Experience with cloud security, particularly within AWS environments.
- Familiarity with OTT platforms, high-traffic streaming ecosystems, or enterprise SaaS products.
- Understanding of threat modeling methodologies and secure code review processes.
- Commitment to ethical standards, ensuring all testing is authorized, documented, and conducted within defined scopes.
- Proactive mindset focused on reducing security risks and validating remediation efforts.
This position offers the opportunity to work in a dynamic environment where security is a top priority. Candidates with experience in high-traffic platforms and cloud ecosystems will find this role particularly rewarding. If you are passionate about cybersecurity and eager to contribute to securing complex systems, we encourage you to apply.