
Job Description
The candidate will be responsible for conducting comprehensive Vulnerability Assessment and Penetration Testing (VAPT) across enterprise IT environments, applications, networks, infrastructure, cloud platforms and security systems.
Key Responsibilities
- Conduct internal and external penetration testing across networks, servers, firewalls, endpoints and infrastructure.
- Perform web application and API penetration testing, including testing against OWASP vulnerabilities.
- Conduct vulnerability assessments and manually validate identified vulnerabilities and false positives.
- Perform controlled exploitation to determine the actual impact and severity of identified security weaknesses.
- Conduct security testing of network devices, firewalls, routers, switches, VPNs, load balancers and servers.
- Perform application security testing covering authentication, authorization, session management, input validation, encryption and business-logic vulnerabilities.
- Conduct source-code security reviews and support SAST/DAST activities.
- Assess security of cloud environments and operating systems.
- Perform security assessments using tools such as Burp Suite, Nmap, Nessus, Metasploit, Wireshark and Kali Linux.
- Develop or automate penetration-testing/security activities using Python.
- Prepare detailed penetration-testing and vulnerability-assessment reports containing evidence, risk ratings, business impact and remediation recommendations.
- Work with technical teams to remediate identified vulnerabilities.
- Conduct retesting and validation after remediation.
- Follow established penetration-testing methodologies and cybersecurity best practices.
Required Technical Skills
Strong hands-on knowledge of:
- Vulnerability Assessment & Penetration Testing (VAPT)
- Network Penetration Testing
- Web Application Penetration Testing
- API Security Testing
- Infrastructure Security Testing
- Cloud Security Testing
- Vulnerability Exploitation & Validation
- OWASP Top 10
- SAST & DAST
- Source-Code Security Analysis
- Secure Coding Practices
- Network & Operating System Security
- Python/Security Automation
- Burp Suite
- Nmap
- Nessus
- Metasploit
- Wireshark
- Kali Linux
Requirements
Standards / Framework Knowledge
The candidate should have good knowledge of relevant cybersecurity standards and methodologies, including:
- OWASP
- NIST
- ISO/IEC 27001
- PCI DSS
- Penetration-testing methodologies and security best practices
Other jobs you might like
Senior Product Security Engineer (f/m/d)
Berlin, DE
Senior Digital Engineer (DevScopes)
Noida, UP, IN
Working at BAE Systems

3 office days / week – Hybrid options are dependant on role and can range from fully remote to on-site full time

A little flex time – We offer a range of hybrid and flexible working arrangements depending on the role you apply for – explore your options with our recruiter during the application process.
