VAPT Lead
adani capital pvt ltdJob Description
VAPT Lead
Responsibilities
VAPT Lead
Vulnerability Assessment and Penetration Testing (VAPT):
Lead and manage comprehensive VAPT activities across the organization’s infrastructure, applications, and network systems.
Plan and scope penetration tests and vulnerability assessments based on organizational needs and potential risks.
Perform vulnerability scanning, manual testing, and exploitations of identified vulnerabilities.
Conduct internal and external penetration testing to identify potential weaknesses in systems, applications, and networks.
Perform risk assessments and prioritize remediation based on business impact and severity.
Team Leadership and Management:
Lead and mentor a team of security professionals, including penetration testers and vulnerability assessors.
Allocate resources effectively for different VAPT projects and ensure timely execution of testing activities.
Provide coaching, guidance, and training to junior team members to foster a growth environment and enhance skill sets.
Ensure adherence to best practices, policies, and ethical standards while conducting penetration testing.
Collaboration with Other Cybersecurity Teams:
Work closely with security operations, incident response, and other teams to share findings and ensure alignment between security testing and overall security strategy.
Provide security recommendations for remediation based on findings from VAPT assessments and assist with the implementation of mitigation strategies.
Collaborate with development teams, IT, and system administrators to support vulnerability remediation efforts.
Reporting and Documentation:
Prepare comprehensive reports on VAPT findings, including vulnerabilities discovered, risk assessments, exploitability, and recommended remediations.
Provide both high-level executive summaries and detailed technical reports for different stakeholders (management, technical teams, etc.).
Track the progress of vulnerabilities remediation and provide regular updates to senior leadership.
Security Standards and Compliance:
Ensure that penetration testing and vulnerability assessments follow relevant security frameworks, industry standards, and compliance regulations (e.g., OWASP, NIST, ISO 27001, GDPR).
Perform regular assessments of compliance requirements and security controls to ensure adherence to security policies.
Contribute to the development of organizational policies and guidelines related to vulnerability management, penetration testing, and overall security best practices.
Security Tools and Technologies:
Lead the selection, deployment, and management of security tools and technologies used for vulnerability assessments, penetration testing, and exploit research (e.g., Nessus, Burp Suite, Metasploit, Nmap, etc.).
Continuously evaluate and improve the use of security tools to enhance testing capabilities and ensure efficiency.
Threat Intelligence and Research:
Stay up-to-date with the latest cybersecurity threats, attack methods, vulnerabilities, and industry trends.
Conduct research to identify emerging security threats and testing techniques and incorporate them into testing methodologies.
Maintain knowledge of advanced attack techniques and tools to simulate real-world attacks and improve testing accuracy.
Continuous Improvement:
Continuously improve testing methodologies, processes, and workflows to increase the effectiveness of VAPT efforts.
Develop and implement new strategies for proactive vulnerability management and penetration testing based on lessons learned and evolving threats.
Advocate for continuous improvement of the organization’s overall security posture based on VAPT findings and industry best practices.
Incident Response and Forensics:
Support the incident response team in analyzing vulnerabilities related to security incidents, providing insights into the potential exploitation of discovered vulnerabilities.
Assist in the development of incident response plans, particularly in relation to vulnerability management and exploitation scenarios.
Key Stakeholders - Internal
Chief Information Security Officer (CISO)
Business Unit Heads and Department Heads
Information Security and IT teams
Risk Management Teams
Security Operations Team
Engineering & Development Teams
Incident Response Teams
Key Stakeholders - External
Regulatory Authorities
Third-Party Service Providers
Qualifications
Educational Qualification:
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Advanced degree (e.g., Master's, MBA) in Cybersecurity, Information Assurance, or a relevant discipline is highly desirable.
Certification:
Certifications:
Relevant certifications such as Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), or GIAC Penetration Tester (GPEN) are highly preferred.
Extensive experience with vulnerability scanning tools (e.g., Nessus, OpenVAS), web application testing tools (e.g., Burp Suite), and penetration testing frameworks.
Deep knowledge of common web and network vulnerabilities (e.g., SQL injection, XSS, buffer overflows, etc.) and security tools.
Experience with scripting and automation (e.g., Python, Bash, PowerShell) is a plus.
Work Experience (Range of years):
5+ years of hands-on experience in penetration testing, vulnerability assessment, and ethical hacking.
Job role
Job requirements
About company
Similar jobs you can apply for
Manufacturing / ProductionGraduate Engineering Trainee
Synnoptech Cad Solutions Llp
Desktop Support Engineer
Mnet TechnologiesComputer Hardware & Network Engineer
Computech Systems
Network Administrator
Raghuvir Synthetics LtdCustomer Relationship Executive
Kataria Automobiles
Desktop Support Engineer
Rhyom Technologies Private LimitedYou can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.
The candidate should have completed the required education and people who have 5 to 31 years are eligible to apply for this job. You can apply for more jobs in Ahmedabad to get hired quickly.
The candidate should have sound communication skills and sound communication skills for this job.
Both Male and Female candidates can apply for this job.
No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Ahmedabad at apna.
No work-related deposit needs to be made during your employment with the company.
Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.
The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Ahmedabad . Through apna, you can find jobs in 64 cities across India. Join NOW!