01Key Responsibilities
- Lead end-to-end Vulnerability Assessment and Penetration Testing (VAPT) engagements across web applications, mobile applications, APIs, cloud environments, and enterprise infrastructure.- Plan, execute, and manage penetration testing activities for internal and external applications, networks, databases, servers, firewalls, endpoints, and cloud platforms.- Perform advanced manual penetration testing to identify complex vulnerabilities that may not be detected through automated tools.- Conduct authenticated and unauthenticated security assessments using industry-standard methodologies and tools.- Assess applications against the latest OWASP Top 10, OWASP API Security Top 10, SANS Top 25, and other industry-recognized security standards.- Perform API security testing for REST, SOAP, GraphQL, OAuth, JWT, and microservices-based architectures.- Conduct mobile application security assessments for Android and iOS platforms, identifying weaknesses in authentication, data storage, encryption, and communication.- Perform infrastructure and network security assessments covering Windows, Linux, Active Directory, databases, firewalls, VPNs, wireless networks, and cloud services.- Lead secure source code reviews to identify insecure coding practices, security flaws, and architectural weaknesses.- Analyze vulnerabilities, assign CVSS scores, determine business impact, and prioritize remediation based on risk.- Prepare detailed VAPT reports including executive summaries, technical findings, proof of concept, screenshots, exploit evidence, and actionable remediation recommendations.- Validate remediation efforts by conducting re-testing and issuing vulnerability closure reports.- Review and validate third-party penetration testing reports and ensure findings meet organizational security standards.- Provide technical guidance to development, DevOps, infrastructure, and architecture teams on secure design principles and vulnerability remediation.- Support implementation of Secure SDLC and DevSecOps practices across application development lifecycles.- Participate in threat modeling, security architecture reviews, and application security assessments during project design phases.- Align security testing activities with ISO 27001, RBI Cyber Security Framework, PCI DSS, NIST, CIS Controls, and other regulatory requirements.- Support internal and external security audits, regulatory assessments, and compliance reviews.- Develop, maintain, and enhance penetration testing methodologies, testing playbooks, and security assessment frameworks.- Mentor junior VAPT consultants by reviewing assessment reports, providing technical guidance, and promoting best practices.- Stay updated on emerging cyber threats, exploit techniques, zero-day vulnerabilities, and evolving attack vectors.- Collaborate with Security Operations, Incident Response, Infrastructure, Cloud, and Product Engineering teams to improve the organization's security maturity.Experience:- 10-15 years of experience in Application Security, VAPT, Penetration Testing, or Offensive Security.- Proven experience leading enterprise VAPT engagements across web, mobile, API, network, and cloud environments.- Strong background in secure code review and security architecture assessments.- Experience in Banking, Financial Services, FinTech, or other highly regulated industries is highly preferred.- Hands-on experience with compliance frameworks such as ISO 27001, PCI DSS, and RBI cybersecurity guidelines. (ref:hirist.tech) .