Conduct cloud security assessments across hyperscalers including AWS, Microsoft Azure, and Google Cloud Platform, evaluating configurations against security baselines and benchmarks (e.g., CIS Benchmarks, cloud provider security frameworks, CSA CCM).
Perform cloud-focused security testing, including vulnerability assessments and penetration testing of cloud infrastructure, cloud-native applications, APIs, and containerized workloads.
Simulate cyber attacks against cloud environments to identify configuration weaknesses, privilege escalation paths, and exploitable vulnerabilities.
...
Education / Experience:Degree in Computer Engineering, Computer Science, Information Systems, Digital Forensics or equivalent qualificationsMinimum 2 years’ of relevant work experience in IT security implementation and operationsPossessed OSCP or attained CREST
Job Description:Perform application and infrastructure penetration tests for customersConducting application security assessments and penetration tests (web, mobile, web service, etc.). Assessments involve manual testing and analysis as well as the use of automated application vulnerability scanning/testing and/or code review tools i.e. Burp Suite Professional, HP Fortify or CheckmarxWriting a formal security assessment report for each application, using our company’s standard reporting formatParticipating in conference calls or on client’s site with potential client to scope out newly requested security projects and estimate the amount of time required to complete the project and current clients to review assessment results and consult with the clients on remediation optionsRetesting security vulnerabilities and republishing reports to indicate the retesting resultsPerform security reviews of application designs, source code and deployments as required, covering all types of applications (web application, web services, mobile applications, thick client applications, SaaS)Work on improvements for provided security services, including the continuous enhancement of existing methodology material and supporting assets
Skill sets:Experience with various security tools and products (Fortify, AppScan, Nessus etc)Several years of experience developing web and/or mobile applications, preferably hard-core financial, e-commerce, or business applications that face the Internet requiredKnowledge of the HTTP protocol and how it worksExperience performing application security testing using manual techniques plus runtime vulnerability testing tools and/or code review tools
Assist in Cyber Defense and Threat Intel operations, such as research in threat and control effectiveness, researching on threat landscape and evaluating new sources of intelligence or solution.
Work closely with SOC analysts to enhance relevant metrics and dashboards.
Develop scripts to facilitate automations. Learning Outcomes:
...
Lead the planning, execution, and delivery of Vulnerability Assessment and Penetration Testing (VAPT) engagements across network, application, endpoint, cloud, and hybrid environments.
Execute and support advanced red team operations, adversary emulation exercises, and threat simulations to assess the effectiveness of security controls, detection capabilities, and incident response processes.
Partner with client stakeholders and internal teams to define engagement scope, objectives, rules of engagement, and risk priorities.
...
Perform hands-on security assessments and compliance testing across web applications, mobile applications, APIs, infrastructure, and cloud environments, aligned with regulatory and industry standards such as MAS TRM, OWASP, and CIS benchmarks.
Conduct web and mobile application penetration testing, including authentication, session management, business logic, and API security testing based on OWASP methodologies (e.g., OWASP Top 10, OWASP ASVS, OWASP MSTG).
Perform infrastructure and network security assessments, including internal/external penetration testing, configuration reviews, and vulnerability validation.
...
Own and manage Security Testing engagements end-to-end from scoping, scheduling, resource allocation, execution, quality review, reporting, and closure within strict, time-sensitive deadlines.
Manage multiple concurrent projects simultaneously, ensuring adherence to SLAs, timelines, and quality benchmarks.
Develop and maintain project plans, trackers, and status dashboards for all active engagements.
...
Plan and execute quarterly vulnerability assessments across the bank's full infrastructure, applications, and API surface. Sr VAPT Engineers own and lead the programme; VAPT Engineers execute assessments and triage findings.
Coordinate the annual intelligence-led penetration test covering internal network, external perimeter, applications, and APIs. Sr VAPT Engineers scope, manage, and validate; VAPT Engineers support execution.
Lead the bank's triennial red team simulation — intelligence-led, adversary-simulated exercises targeting critical banking systems. Sr VAPT Engineers lead; VAPT Engineers participate and develop skills.
...
To provide information security services for clients, including but not limited to Posture Assessment, Gap Assessment, Risk Assessment, implementation and review of policies and procedures, Security Awareness Training, and tabletop exercises..
To provide service deliverables in accordance with the mutually agreed Scope Of Work (SOW).
To provide consultation and advisory service on event/ attack mitigation, advanced incident management and reporting analysis and cybersecurity monitoring solution best practices.
...