Enter a job title or keyword

VAPT Security Engineer

Alignity Solutions


Job Location:

Hyderabad - India

Salary: Not provided by the employer
Experience Required: 3-5years
Posted: 18 September 2026 (16 hours ago)
Application Deadline: 16 December 2026
Vacancies: 1 Vacancy

Job Summary

Do you love a career where you Experience Grow & Contribute at the same time while earning at least 10% above the market If so we are excited to have bumped onto you.

If you are a Penetration Testing Senior Consultant looking for excitement challenge and stability in your work then you would be glad to come across this page.

We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.

Check if you are up for maximizing your earning/growth potential leveraging our Disruptive Talent Solution.

Role:Penetration Testing Senior Consultant
Location: Hyderabad Bengaluru Pune Chennai Kolkata
Experience:3-5 Years
Work Mode: Hybrid
Type: Contract to Hire
Notice Period:Immediate Joiners


Requirements

As a Penetration Testing Senior Consultant you will lead the execution of offensive security engagements and help clients identify validate and remediate security vulnerabilities across their digital ecosystem.

You will work across application API mobile thick-client network cloud and enterprise infrastructure environments while collaborating with technical and business stakeholders to translate security findings into actionable business risk and remediation recommendations.


Key Responsibilities

  • Lead penetration testing workstreams across web applications APIs mobile thick-client network cloud and infrastructure environments.
  • Design test plans and execute manual and automated security assessments.
  • Identify validate exploit and document security vulnerabilities.
  • Perform manual testing for vulnerabilities including:
    • SQL Injection / Blind SQL Injection
    • XSS and CSRF
    • XXE
    • SSRF
    • Insecure Deserialization
    • HTTP Request Smuggling
    • Authentication & Authorization weaknesses
    • Business Logic vulnerabilities
  • Assess OAuth 2.0 OpenID Connect session management identity and access controls.
  • Conduct secure code reviews using OWASP Secure Coding Practices or comparable methodologies.
  • Perform application security architecture reviews and threat modeling.
  • Conduct vulnerability assessments across application infrastructure cloud mobile and enterprise environments.
  • Use industry-standard security testing tools such as Burp Suite Fiddler Wireshark Nmap Metasploit Nessus Qualys Tenable Veracode Frida Apktool JADX dnSpy and IDA Pro.
  • Develop scripts and automation using Python PowerShell Bash or similar technologies to improve reconnaissance testing evidence collection and reporting.
  • Support purple team red team adversarial simulation and threat-informed testing activities.
  • Map attack scenarios and findings to MITRE ATT&CK and relevant threat behaviors.
  • Coordinate with application infrastructure cloud development and security operations teams for remediation and retesting.
  • Prepare detailed technical reports executive summaries risk-based findings remediation recommendations and client presentations.
  • Translate technical vulnerabilities into business-relevant risk statements and prioritized remediation plans.
  • Support engagement planning estimation proposal development solution development and identification of follow-on opportunities.
  • Mentor junior team members and review technical deliverables.
  • Provide technical and professional feedback to team members.
  • Prepare daily weekly quarterly and annual status reports and remediation tracking materials.
  • Respond to ad-hoc research reporting and technical requests from management and clients.
  • Adhere to internal security requirements and Deloitte policies.
Must-Have Skills & Experience
  • 7 years of hands-on cybersecurity experience in penetration testing application security cyber risk vulnerability assessment or related technical security roles.
  • Proven experience conducting penetration testing across multiple domains:
    • Web Applications
    • APIs
    • Mobile Applications
    • Thick-Client Applications
    • Networks
    • Cloud
    • Enterprise Infrastructure
  • Strong knowledge of OWASP Top 10 and application security vulnerabilities.
  • Strong hands-on experience with manual vulnerability assessment and exploitation.
  • Strong understanding of:
    • OAuth 2.0
    • OpenID Connect
    • Identity Management
    • Session Management
    • Access Control
  • Experience with secure code reviews.
  • Strong hands-on experience with manual penetration testing combined with automated security tools.
  • Proficiency with tools such as:
    Burp Suite Fiddler Wireshark Nmap Metasploit Nessus Qualys Tenable Veracode Frida Apktool JADX dnSpy IDA Pro or equivalent.
  • Strong understanding of web application architecture including frontend backend databases APIs application servers and middleware.
  • Knowledge of HTML CSS JavaScript PHP and backend databases.
  • Experience with application security architecture assessment and threat modeling.
  • Understanding of basic reverse engineering and memory analysis concepts.
  • Strong understanding of networking protocols including TCP/IP DNS HTTP/HTTPS SMB and LDAP.
  • Familiarity with CVE and CVSS.
  • Excellent technical documentation and report-writing skills.
  • Strong analytical problem-solving prioritization and stakeholder-management skills.
  • At least one relevant cybersecurity certification such as:
    OSCP OSWP GPEN GWAPT BSCP OSWE CISSP or CREST certification.
Good-to-Have Skills
  • Application infrastructure cloud mobile and microservices security assessment experience.
  • Experience testing AI-enabled applications LLM integrations APIs AI agents or related systems.
  • Red Team Purple Team breach attack simulation or adversary emulation experience.
  • Knowledge of:
    • MITRE ATT&CK
    • Cyber Kill Chain
    • SANS Top 25
    • Threat-informed penetration testing
  • Experience with offensive security tools such as Cobalt Strike Sliver BloodHound Empire Metasploit Nmap Qualys and Tenable.
  • Knowledge of Active Directory security privilege escalation lateral movement identity attacks and enterprise misconfigurations.
  • Experience assessing AWS Azure or GCP environments including IAM storage compute networking containers and Kubernetes.
  • Familiarity with security monitoring platforms such as Microsoft Defender CrowdStrike SentinelOne Carbon Black Splunk QRadar and ArcSight.
  • Working knowledge of malware analysis reverse engineering binary analysis exploit development or memory analysis.
  • Security automation and scripting experience using Python PowerShell Bash or similar languages.
  • Ability to translate threat intelligence into realistic and controlled attack scenarios.
  • Experience presenting security findings to both technical and executive audiences.
  • Security research publications blogs open-source projects conference presentations or CVEs.
  • Preferred certifications: OSWE OSEP OSED OSCE3 CRTO GXPN OSEE AWS Security Specialty SABSA or CREST offensive security certifications.
  • Familiarity with NIST PCI DSS HIPAA GDPR and other relevant cybersecurity/privacy standards.
  • Strong written and verbal English communication skills.
  • Strong interest in continuous learning and developing new offensive security techniques.


Benefits

CEO Message: Click Here
Clients Testimonial: Click Here


Required Skills:

7 years of hands-on experience in cybersecurity cyber risk services application security vulnerability assessment penetration testing or related technical security roles. Demonstrated experience conducting penetration tests across multiple domains including web applications APIs mobile applications thick-client applications networks cloud environments or enterprise infrastructure. Strong understanding of the OWASP Top 10 and related application security vulnerabilities. Strong experience with manual assessment and exploitation of vulnerabilities such as: o SQL injection and blind SQL injection o Cross-site scripting and request forgery o XML external entity attacks o Server-side request forgery o Insecure deserialization o HTTP request smuggling o Authentication and authorization weaknesses o Business logic vulnerabilities Strong understanding of OAuth 2.0 OpenID Connect identity management session management and access-control vulnerabilities. Experience performing secure code reviews using OWASP Secure Coding Practices or comparable methodologies. Ability to perform manual penetration testing while effectively using automated security assessment tools. Proficiency with tools such as Burp Suite Fiddler Wireshark Nmap Metasploit Nessus Qualys Tenable Veracode Frida Apktool JADX dnSpy IDA Pro or comparable tools. Knowledge of web application components including frontend backend databases APIs application servers and middleware. Understanding of web development technologies such as HTML CSS JavaScript PHP and backend databases. Experience reviewing application security architecture and performing threat modeling. Understanding of basic reverse engineering and memory analysis concepts. Understanding of networking protocols including TCP/IP DNS HTTP HTTPS SMB and LDAP. Familiarity with vulnerability classification frameworks and terminology including CVE and CVSS. Excellent technical report writing skills including the ability to document evidence business impact risk and remediation recommendations. Strong analytical problem-solving prioritization and stakeholder management skills. One or more relevant cybersecurity certifications such as OSCP OSWP GPEN GWAPT BSCP OSWE CISSP or CREST Certified Simulated Attack Specialist.


Required Education:

BE / / MCA / . in Computer Science or equivalent degree from an accredited university.