Talent.com
Security Vulnerability Assessment Lead
Security Vulnerability Assessment LeadShieldByte Infosec Pvt. Ltd. • Republic Of India, IN
Security Vulnerability Assessment Lead

Security Vulnerability Assessment Lead

ShieldByte Infosec Pvt. Ltd. • Republic Of India, IN
9 hours ago
Job description

Location : Ghatkopar, Mumbai (Onsite)

Department : Information Security / Offensive Security

Experience : 2–8 Years

Certifications Preferred : OSCP, CEH, eCPPT, eJPT, GWAPT, or equivalent

About the Role

We are seeking a highly skilled Cybersecurity Analyst (Vulnerability Assessment & Penetration Testing) specializing in both Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) . The ideal candidate will have hands-on experience performing end-to-end security testing across web applications, mobile apps (Android / iOS), APIs, networks, Active Directory environments, and source code.

This role requires a strong understanding of offensive security, exploit development, red teaming methodologies, and secure coding practices to identify, exploit, and document vulnerabilities with actionable recommendations.

Key Responsibilities

  • Conduct Vulnerability Assessments and Penetration Tests (VAPT) across :
  • Web applications, APIs, and backend services
  • Android and iOS mobile applications
  • Corporate and cloud networks
  • Active Directory and internal infrastructure
  • Perform SAST & DAST on custom applications using manual and automated tools.
  • Analyze source code (Java, Python, PHP, .NET, etc.) to identify logic flaws and insecure coding practices.
  • Execute Red Team exercises , simulate attack chains, and evaluate defense mechanisms.
  • Generate detailed technical reports with PoC evidence, exploit steps, risk severity, and remediation guidance.
  • Collaborate with development and DevSecOps teams to verify fixes and retests.
  • Maintain up-to-date knowledge of the latest vulnerabilities, exploits, and security tools.
  • Support compliance assessments and cybersecurity trends.

Required Skills and Expertise

  • Strong knowledge of OWASP Top 10 , SANS CWE 25 , and MITRE ATT&CK frameworks.
  • Hands-on experience with tools like Burp Suite, ZAP, Metasploit, Nmap, Nessus, Nikto, MobSF, Frida, Drozer, Postman, SQLMap , etc.
  • Deep understanding of authentication flaws, insecure direct object references, API abuse, and privilege escalation.
  • Practical experience with Active Directory attacks (Kerberoasting, Pass-the-Hash, LLMNR poisoning, etc.)
  • Proficiency in scripting languages (Python, Bash, PowerShell) and code review.
  • Excellent analytical, reporting, and communication skills.
  • Certifications (Preferred but not Mandatory)

  • Offensive Security Certified Professional (OSCP)
  • Certified Ethical Hacker (CEH)
  • eLearnSecurity Certified Professional Penetration Tester (eCPPT)
  • GIAC Penetration Tester (GPEN)
  • eWPT / eWPTX / eJPT
  • Educational Qualification

  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or related field.
  • Equivalent hands-on experience may be considered as a substitute for formal education.
  • Why Join Us

  • Opportunity to work on real-world red teaming engagements and advanced VAPT projects.
  • Exposure to global clients in the BFSI, IT, and healthcare domains.
  • Continuous learning through internal labs, CTFs, and tool research.
  • Competitive pay, certification sponsorship, and a growth-oriented culture.
  • Create a job alert for this search

    Security Lead • Republic Of India, IN

    Related jobs
    Incident Responder - L3

    Incident Responder - L3

    SQ1 Security • Chennai, Republic Of India, IN
    As an SQ1 Security Cyber Defense Incident Responder within the Global Cybersecurity Operations Center (CSOC), you will serve as a key technical expert responsible for managing and responding to adv...Show more
    Last updated: 19 days ago • Promoted
    AI Security Lead

    AI Security Lead

    Delphi Consulting Middle East • Nagpur, IN
    Join Delphi - Where Innovation meets transformation.At Delphi, we believe in creating an environment where our people thrive. We are committed to supporting your personal goals, family, and overall ...Show more
    Last updated: 3 days ago • Promoted
    Security Operations Engineer Lead

    Security Operations Engineer Lead

    NTT Global Networks • Republic Of India, IN
    Lead Engineer – Network Security Implementation / Network Security Implementation Lead.Strong technical and subject matter expertise in at least four or more of the following security specialties : ....Show more
    Last updated: 1 day ago • Promoted
    Lead Security Engineer

    Lead Security Engineer

    interface.ai • India, India
    Our cutting-edge Generative AI-powered platform serves over 100 banks and credit unions, delivering hyper-personalized customer interactions across voice, chat, and employee-assisting solutions.To ...Show more
    Last updated: 30+ days ago • Promoted
    Data Center Security Lead

    Data Center Security Lead

    Securitas India • Chennai, Republic Of India, IN
    We are a dynamic, dedicated team that provides management and support for a global guarding services account that spans across 30+ countries. Our client is an industry-leading datacenter organizatio...Show more
    Last updated: 1 day ago • Promoted
    Security Operations Transformation Lead

    Security Operations Transformation Lead

    Palo Alto Networks • Republic Of India, IN
    At Palo Alto Networks® everything starts and ends with our mission : .Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and m...Show more
    Last updated: 1 day ago • Promoted
    Security Operations Engineer

    Security Operations Engineer

    ITPeopleNetwork • nagpur, maharashtra, in
    We are looking for a junior to mid-level.Saviynt Identity Access Management (IAM / IGA).CyberArk Endpoint Privilege Manager (EPM). The ideal candidate will assist in user access governance, email thre...Show more
    Last updated: 2 days ago • Promoted
    Soc Analyst L2 / L3 (Immediate Joiners)

    Soc Analyst L2 / L3 (Immediate Joiners)

    Inspira Enterprise • Republic Of India, IN
    The L2 / L3 Security SOC Analyst operates security monitoring solutions, reacting promptly to security events.The role involves providing Incident Response (IR) support when analysis confirms actiona...Show more
    Last updated: 5 hours ago • Promoted • New!
    Cybersecurity Incident Responder

    Cybersecurity Incident Responder

    Inspira Enterprise • Republic Of India, IN
    The L2 / L3 Security SOC Analyst operates security monitoring solutions, reacting promptly to security events.The role involves providing Incident Response (IR) support when analysis confirms actiona...Show more
    Last updated: 9 hours ago • Promoted • New!
    Security Operations Center Analyst

    Security Operations Center Analyst

    Inspira Enterprise • Republic Of India, IN
    The L2 / L3 Security SOC Analyst operates security monitoring solutions, reacting promptly to security events.The role involves providing Incident Response (IR) support when analysis confirms actiona...Show more
    Last updated: 9 hours ago • Promoted • New!
    Pinnacle Teleservices - Security Engineer - Vulnerability Assessment

    Pinnacle Teleservices - Security Engineer - Vulnerability Assessment

    Pinnacle Teleservices Pvt Ltd • Nagpur
    Job Description : We are looking for a Cross Function Security Technology Support Engineer, who will become part of our Security Technology Operation...Show more
    Last updated: 11 days ago • Promoted
    Vice President - Security (Purple Fabric, Intellectai)

    Vice President - Security (Purple Fabric, Intellectai)

    Intellect Design Arena Ltd • Chennai, Republic Of India, IN
    Build the security and testing strategy for.AI platform powering mission-critical workflows for leading BFSI institutions. Product, Engineering, QA, Platform, Data Privacy, Compliance, and Customer ...Show more
    Last updated: 12 days ago • Promoted
    Lead Security Engineer

    Lead Security Engineer

    Arcana • India, India
    As our Lead Security Engineer, you'll own and elevate Arcana's overall security posture - cloud, on-prem, and everything in between. You'll design and enforce policies, automate controls, and harden...Show more
    Last updated: 30+ days ago • Promoted
    Team Lead

    Team Lead

    ALTISOURCE BUSINESS SOLUTIONS PRIVATE LIMITED • Nagpur, IN
    Willing to work in night shift.Lead the property inspection operations in a multi-client environment ensuring adherence to service level agreements and quality standards. Track team perfoJob Descrip...Show more
    Last updated: 10 days ago • Promoted
    Yoda Technologies - Security Operations Lead - SIEM Tools

    Yoda Technologies - Security Operations Lead - SIEM Tools

    Yoda Technologies Pty Ltd • India
    About the Role : We are seeking an experienced SecOps Lead to oversee and enhance our global security operations function.This role will be respons...Show more
    Last updated: 30+ days ago • Promoted
    Lead Security Engineer

    Lead Security Engineer

    PINKVILLA • Republic Of India, IN
    Pinkvilla is seeking a dynamic Information Security professional, who will contribute to strengthening our security posture by working closely with cross-functional teams, monitoring threats, secur...Show more
    Last updated: 1 day ago • Promoted
    Security Operations Lead

    Security Operations Lead

    NTT Global Networks • Republic Of India, IN
    Lead Engineer – Security Operations.Strong technical and subject matter expertise in at least four or more of the following security specialties : . Firewall : Cisco, Palo Alto, Checkpoint, Fortinet, Z...Show more
    Last updated: 1 day ago • Promoted
    Data Loss Prevention Engineering Lead

    Data Loss Prevention Engineering Lead

    TransUnion • Chennai, Republic Of India, IN
    TransUnion’s Global Information Security organization is seeking a passionate and experienced leader to join our Global Insider Threat Program as Manager – Insider Threat Engineering.In this role, ...Show more
    Last updated: 1 day ago • Promoted