Job Description
<p></p><p><b>Job Description :</b><br/><br/><b>Experience : 5+ years in Cybersecurity</b><br/><br/><b>Location : Hyderabad</b><br/><br/><b>Job Summary :</b><br/><br/></p><p>We are seeking a seasoned Cyber Security Engineer with a minimum of five (5) years hands-on experience in Vulnerability Assessment & Penetration Testing (VAPT) and security testing across web applications, APIs, networks, and databases.
The ideal candidate will combine strong technical skills in programming and scripting with deep familiarity with industry-standard security standards, tools and methodologies.<br/><br/><b>Key Responsibilities :</b><br/><br/></p><p>Vulnerability Assessment & Penetration Testing :<br/><br/></p><p>- Plan and execute black-box, white-box, and gray-box penetration tests.<br/><br/></p><p>- Identify, analyze, and report security vulnerabilities in web applications, REST/SOAP APIs, network infrastructures, and database systems.<br/><br/></p><p>Security Testing :<br/><br/></p><p>- Perform security code reviews and static/dynamic analysis on application source code.<br/><br/></p><p>- Execute automated and manual security test cases, including OWASP Top 10, SANS Top 25, and API-specific risks.<br/><br/></p><p>Tooling & Automation :<br/><br/></p><p>- Develop and maintain custom scripts and tooling to automate reconnaissance, scanning, exploitation, and reporting.<br/><br/></p><p>- Integrate security testing into CI/CD pipelines and DevSecOps workflows.</p><p><br/></p><p>Risk Analysis & Reporting :<br/><br/></p><p>- Assess business impact and prioritize vulnerabilities by severity and exploitability.<br/><br/></p><p>- Produce clear, actionable reports and work with development teams to validate fixes.<br/><br/></p><p>Collaboration & Advisory :<br/><br/></p><p>- Liaise with developers, DevOps, and IT/network teams to remediate security findings.<br/><br/></p><p>- Provide guidance on secure coding practices, hardening configurations, and security best practices.<br/><br/></p><p>- Providing assistance to other teams (project, commercial, product, customer success) in answering cyber security related questions raised by/in customer/project tenders.<br/><br/><b>Required Qualifications :</b><br/><br/></p><p>- Bachelors degree in computer science, Information Security, or related field.<br/><br/></p><p>- 3+ years of professional experience in VAPT and security testing.<br/><br/></p><p>Technical Skills :<br/><br/></p><p>Programming & Scripting : </p><p><br/></p><p>- Proficient in at least two of : Python, Java, C#, Ruby, Go, or JavaScript/TypeScript.<br/><br/></p><p>- Shell scripting (Bash/PowerShell) for automation.<br/><br/></p><p>Security Tools & Frameworks :<br/><br/></p><p>- Web/API testing : Burp Suite, OWASP ZAP, Postman, SoapUI.<br/><br/></p><p>- Network scanning : Nmap, Nessus, OpenVAS.<br/><br/></p><p>- DB security : SQLMap, DbProtect, manual SQL injection testing.<br/><br/></p><p>- Static/Dynamic analysis : SonarQube, Trivy, Fortify, Checkmarx, Veracode.<br/><br/></p><p>Protocols & Technologies :<br/><br/></p><p>- HTTP/S, REST, SOAP, TCP/IP, DNS, LDAP, OAuth/OIDC, JWT.<br/><br/></p><p>- Database platforms : MySQL, PostgreSQL, SQL Server, Oracle.<br/><br/></p><p>Standards & Compliance :<br/><br/></p><p>- Familiarity with OWASP Top 10, SANS Top 25, PCI-DSS, ISO 27001/27002, NIST.<br/><br/><b>Preferred Skills :</b><br/><br/></p><p>- Experience with cloud security testing (AWS, Azure, GCP).<br/><br/></p><p>- Familiarity with container and orchestration security (Docker, Kubernetes).</p><p><br/></p><p>- Certification(s) : OSCP, CEH, CISSP, CISM, or similar.<br/><br/></p><p>- Hands-on in DevSecOps integration and security automation frameworks (e.g., Jenkins, GitLab CI, Terraform).<br/><br/></p><p><b>Soft Skills :<br/></b><br/></p><p>- Strong analytical and problem-solving abilities.<br/><br/></p><p>- Excellent written and verbal communication for clear reporting and stakeholder engagement.<br/><br/></p><p>- Ability to work independently and as part of a cross-functional team.</p><br/><p></p> (ref:hirist.tech)