Security Analyst – VAPT & Penetration Testing
Indexed description
Key Responsibilities
- Conduct internal and external penetration testing across networks, servers, firewalls, endpoints and infrastructure.
- Perform web application and API penetration testing, including testing against OWASP vulnerabilities.
- Conduct vulnerability assessments and manually validate identified vulnerabilities and false positives.
- Perform controlled exploitation to determine the actual impact and severity of identified security weaknesses.
- Conduct security testing of network devices, firewalls, routers, switches, VPNs, load balancers and servers.
- Perform application security testing covering authentication, authorization, session management, input validation, encryption and business-logic vulnerabilities.
- Conduct source-code security reviews and support SAST/DAST activities.
- Assess security of cloud environments and operating systems.
- Perform security assessments using tools such as Burp Suite, Nmap, Nessus, Metasploit, Wireshark and Kali Linux.
- Develop or automate penetration-testing/security activities using Python.
- Prepare detailed penetration-testing and vulnerability-assessment reports containing evidence, risk ratings, business impact and remediation recommendations.
- Work with technical teams to remediate identified vulnerabilities.
- Conduct retesting and validation after remediation.
- Follow established penetration-testing methodologies and cybersecurity best practices.
- Support security teams in identifying attack vectors and improving the organization's overall security posture.
- Vulnerability Assessment & Penetration Testing (VAPT)
- Network Penetration Testing
- Web Application Penetration Testing
- API Security Testing
- Infrastructure Security Testing
- Cloud Security Testing
- Vulnerability Exploitation & Validation
- OWASP Top 10
- SAST & DAST
- Source-Code Security Analysis
- Secure Coding Practices
- Network & Operating System Security
- Python/Security Automation
- Burp Suite
- Nmap
- Nessus
- Metasploit
- Wireshark
- Kali Linux
The candidate should have good knowledge of relevant cybersecurity standards and methodologies, including:
- OWASP
- NIST
- ISO/IEC 27001
- PCI DSS
- Penetration-testing methodologies and security best practices
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search