Key Responsibilities
Lead the planning, execution, and delivery of Vulnerability Assessment and Penetration Testing (VAPT) engagements across network, application, endpoint, cloud, and hybrid environments.
Execute and support advanced red team operations, adversary emulation exercises, and threat simulations to assess the effectiveness of security controls, detection capabilities, and incident response processes.
Partner with client stakeholders and internal teams to define engagement scope, objectives, rules of engagement, and risk priorities.
Identify, validate, and exploit security vulnerabilities using industry-standard methodologies, frameworks, and tools while maintaining high standards of professionalism and ethical conduct.
Analyze threat intelligence, emerging attack techniques, and adversary tactics aligned with frameworks such as MITRE ATT&CK to enhance the effectiveness and relevance of security assessments.
Develop clear, accurate, and executive-ready reports that communicate technical findings, business risks, and prioritized remediation actions.
Mentor junior security practitioners by providing technical guidance, knowledge sharing, and support in offensive security techniques, tooling, and reporting practices.
Contribute to the continuous improvement of VAPT methodologies, red team playbooks, automation capabilities, and service delivery standards to drive operational excellence and client value.
Required Qualifications
Bachelor’s degree in Cyber Security, Information Security, Computer Science, Information Technology, or a related discipline.
Proven experience performing penetration testing, vulnerability assessments, and offensive security engagements across enterprise environments.
Strong hands-on experience with application security testing, network penetration testing, cloud security assessments, and exploitation techniques.
Deep understanding of modern attack methodologies, adversary tactics, and security frameworks, including MITRE ATT&CK and OWASP.
Experience creating technical assessment reports and presenting findings to both technical and non-technical stakeholders.
Strong problem-solving, analytical, and communication skills, with the ability to manage multiple priorities in a dynamic environment.
Ability to collaborate effectively across teams and contribute to key security decisions and strategic initiatives.
Preferred Qualifications
Industry certifications such as OSCP, OSEP, OSWE, CRTO, CREST, GPEN, GWAPT, GXPN, CISSP, or equivalent.
Experience conducting red team operations, purple team exercises, and threat-led security assessments.
Knowledge of cloud platforms such as Microsoft Azure, AWS, and Google Cloud Platform (GCP).
Experience with security automation, scripting, and offensive security tooling.
Familiarity with Security Operations Center (SOC) processes, threat hunting, and detection engineering.