Roles Responsibilities
Conduct Vulnerability Assessments Black-box / Grey-box Penetration tests on System, Network infrastructure, Cloud, Web, APIs (REST SOAP), Mobile (Android +iOS) Thick-client applications using various open source,commercialtoolsandmanualtestingmethods.
Location : Pune, India
Mode of work : Work from office (Daily)
Qualification
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- 8 - 10 years of relevant Experience
- CEH Certified
- CREST / OSCP Certifications will be an added advantage
- MSSP (ManagedSecurityServices Provider) experience supporting multiple customers infrastructure
- Broad background of networks,operating systems(Window,Unix,Linux),firewalls and security engineering concepts
- Knowledge of scripting languages(C++,C#,Perl,CGI,HTML,Java,TCL,Shell)will be added advantage
- Willing to travel overseas on projects
InfrastructureVA / PT
Job Description
Map out a network, discover ports and services running on the different exposed networkandsecuritydevicesConduct penetration test and launch exploits using NMap, Nessus, Metasploit,Backtrack,KaliLinux penetration testing toolssetsResearch and maintain proficiency in computer network exploitation,tools,techniques, counter measures,and trends in computer network vulnerabilities, data hiding,networksecurity,andencryptionAnalyze scan reports and recommend remediation / mitigation actionsKeep track of new vulnerabilities for all relevant technology platformsAudit configuration of OS, Network and Security devicesProvide Cloud Infrastructure AssessmentsProvidingclientspecificreportsUnderstand IT infrastructure and traffic flows to manage VAPT exercisesCommunicate with the customer to understand their needs and address concerns.Application VA / PT
Conduct Web, Mobile (iOS + Android) and Thickclient application assessments based on industrystandards / benchmarks like OWASPConduct assessments using relevant automated toolsandcomplimentwithmanualreviewsSocial Engineering
Conduct phishing and spear-phishing simulated assessments, and techniques in the social engineering domain to assess the adequacy of awareness and training programs in organizations.Required Skills
Experience on Network Vulnerability Scanning and Penetration TestingExperience on Cloud Infrastructure Security AssessmentsExperiencewithNessus,Net Cat,NMAP, Kali,Metasploit,HPing, Frida, Objection, Drozer andsimilartoolssetlikeRetinaCS,QualysKnowledgeofNetworkSecuritytechnologyinareasofFirewall,IPS,VPN,Gatewaysecuritysolutions(DNS, VLAN, proxy, webfiltering)In-depth understandingon Common Vulnerability Exposure (CVE) / Cert advisory databaseAnalyticalthinkerwillingto'thinkout of thebox'to resolve customer impactin situations on first contact;understand customer risk profileKnowledge in RPF preparation, Solution architecture, VAPT review and presentation in customer arenaStrong Presentation and Documentation Skills.Self-starter andabilitytodeliverunderdefinedtimelines, team player with leadership capabilitiesSkills Required
Penetration Testing, Metasploit, Vpn, Vulnerability Assessments, Nessus, Nmap, Dns, Ips, Vlan, Firewall