Security Engineer – VAPT (Vulnerability Assessment & Penetration Testing)
TAC Security · New Delhi
Job description
About the role
As a Security Engineer specializing in Vulnerability Assessment and Penetration Testing (VAPT), you will evaluate web, mobile, API and network environments, identify security weaknesses and guide remediation to strengthen client defenses.
Key responsibilities
- Perform end‑to‑end VAPT for web applications, mobile applications (iOS & Android), APIs, network infrastructure and enterprise IT environments.
- Conduct assessments using industry‑standard tools such as Burp Suite, Nmap, Nessus, Metasploit, OWASP ZAP, MobSF, Frida, Drozer and Postman.
- Execute web application testing based on OWASP Top 10 guidelines.
- Carry out mobile application security testing (static and dynamic) following OWASP Mobile Top 10.
- Test APIs against OWASP API Security Top 10, covering authentication, authorization, business logic and misconfiguration.
- Identify, validate and exploit vulnerabilities, then produce detailed reports with findings, risk ratings, PoCs and remediation recommendations.
- Collaborate with development and infrastructure teams to prioritize and remediate identified issues.
- Develop custom scripts and automate repetitive testing tasks using Python, Bash or PowerShell.
- Participate in validation, remediation verification and re‑testing activities.
- Stay current on emerging threats, CVEs, attack techniques and best practices, and share knowledge with junior engineers.
Required profile
- Bachelor’s degree in Computer Science, Information Technology or a related field.
- 2–3 years of hands‑on VAPT experience on web, mobile and API platforms.
- Practical experience with Windows, Linux and Unix operating systems.
- Strong understanding of network protocols, web application architecture and common security vulnerabilities.
- Relevant certifications such as CEH or OSCP are preferred.
- Excellent analytical skills, attention to detail and ability to manage multiple tasks.
- Effective verbal and written communication skills.
Required skills
- Python
- Bash
- PowerShell
- Burp Suite
- Nmap
- Nessus
- Metasploit
- OWASP ZAP
- MobSF
- Frida
- Drozer
- Postman
- Windows
- Linux
- Unix
- API testing
- Static analysis
- Dynamic analysis
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in India.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 month ago
Expires 1 week from now
72 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
TAC Security
New Delhi
Related job offers
-
Security Engineer – Container & Cloud Security
CARPL - Radiology AI Platform New Delhi -
Full Stack Backend Developer
revenuebase-inc New Delhi -
Engineering Manager, Full Stack & Front End (AI)
Agoda New Delhi -
IT Support Specialist – Tier 1/2 – Chennai
Husky Technologies Chennai -
Android Mobile Developer
Asymmetric Labs Bengaluru