Job Title: Senior Cyber Security Consultant
Location: ThaneMumbai
Job Type: Fulltime
Experience: Minimum 3 years of relevant experience
Educational Requirements: Engineering Graduate in CS IT EC InfoSec Cyber Security or MCA equivalent
About Us
Our Client is a leader in cybersecurity services dedicated to safeguarding organizations from cyber threats through innovative security solutions. We are expanding our team and seeking a Senior Cyber Security Consultant to oversee and manage Vulnerability Assessment and Penetration Testing (VAPT) activities for clients web applications.
Job Description
We are looking for a highly skilled and experienced Senior Security Consultant to join our cybersecurity team. The ideal candidate will be responsible for overseeing and leading VAPT activities providing remediation support and ensuring the closure of vulnerabilities. You will work closely with clients manage a team of vulnerability scanners and help develop and implement strategies to mitigate cybersecurity risks. The role offers the opportunity to work with cuttingedge technologies and to stay at the forefront of cybersecurity developments.
Roles & Responsibilities
- Lead and support remediation efforts to ensure the effective closure of identified vulnerabilities.
- Oversee and track open vulnerabilities utilizing the escalation matrix when necessary to ensure timely resolution.
- Conduct regular audits to ensure compliance with internal security practices and standards.
- Keep uptodate with the latest cybersecurity technologies ensuring that the organization remains at the forefront of security.
- Manage a team of vulnerability scanners guiding and mentoring them in their daily tasks and ensuring highquality assessments.
- Research and maintain expertise in areas like network exploitation data hiding encryption network security and emerging cybersecurity trends.
- Perform thorough analysis of VAPT results review reports and provide risk mitigation strategies and recommendations based on the findings.
- Fulfill additional tasks and responsibilities based on client requirements.
Key Skills & Requirements
- Indepth knowledge of security vulnerabilities exploitation techniques and remediation practices.
- Handson experience in conducting Vulnerability Assessments & Penetration Testing (both automated and manual) on businesscritical assets.
- Proficiency with wellknown security tools such as BurpSuite Nessus Nmap Accunetix Metasploit Netsparker Qualys and similar tools.
- Strong experience in mobile application security assessments (Android & iOS).
- Deep understanding of Common Vulnerability Exposure (CVE) and Common Weakness Enumeration (CWE).
- Extensive knowledge of Network Security technologies including Firewalls IPS VPNs and Gateway security solutions (proxy web filtering).
- Ability to perform detailed analysis of VAPT results and provide effective risk mitigation and security recommendations.
- Minimum of 3 years of relevant experience in cybersecurity consulting penetration testing and vulnerability assessments.
- Familiarity with OWASP Top 10 SANS Top 25 vulnerabilities and validation techniques in source code along with other security frameworks and compliance standards.
- Strong understanding of Cloud Security and emerging trends in the field.
Desired Candidate Profile
- Educational Background: Engineering Graduate in CS IT EC InfoSec Cyber Security or MCA equivalent.
- Certifications: eJPT CEH or similar certifications are highly preferred.
- Experience: At least 3 years of relevant experience in VAPT and cybersecurity consulting.
- Skills:
- Strong organizational and multitasking abilities with excellent time management skills.
- Knowledge of Thick Client Security assessments.
- Outstanding communication abilities with the capability to clearly explain complex security solutions to both technical and nontechnical stakeholders.
- Ability to thrive in a fastpaced environment and under pressure.
- Strong attention to detail analytical mindset and problemsolving skills.
- Solid understanding of MITRE ATT&CK and D3FENCE frameworks.
- Keen awareness of the latest cybersecurity trends and attacking techniques.