β‘ New
Security Analyst
Certbar Security
MumbaiFull-timeMid LevelOn-site
Job Description
Position Title: Security Analyst
Location: Surat / Mumbai
Experience: 1β3 Years
Employment Type: Full-time
Job Summary
We are looking for a Security Analyst with 1β3 years of hands-on experience in Vulnerability Assessment, Penetration Testing (VAPT), and security testing. The candidate will be responsible for identifying security vulnerabilities, validating security risks, documenting findings, and supporting remediation activities across applications, APIs, networks, and infrastructure.
Key Responsibilities
- Perform manual and automated Vulnerability Assessment and Penetration Testing (VAPT).
- Conduct security assessments of web applications, APIs, mobile applications, networks, and infrastructure.
- Identify, validate, and document security vulnerabilities and misconfigurations.
- Perform manual testing to identify vulnerabilities that may not be detected by automated scanners.
- Perform vulnerability scanning, manual validation, exploitation, and proof-of-concept (PoC) development where applicable.
- Analyse vulnerability severity, business impact, and associated risks.
- Prepare detailed technical and executive security assessment reports, including vulnerability description, risk rating, evidence/PoC, reproduction steps, impact, and remediation recommendations.
- Conduct retesting to validate that reported vulnerabilities have been properly remediated.
- Work with development, infrastructure, and IT teams to understand and communicate security findings.
- Participate in client discussions, security assessment walkthroughs, and remediation discussions when required.
- Stay updated on new vulnerabilities, CVEs, attack techniques, and cybersecurity trends.
- Follow established security testing methodologies, standards, and best practices.
Required Skills & Qualifications
- 1β3 years of hands-on experience in Cybersecurity, VAPT, Penetration Testing, Application Security, or a related role.
- Good understanding of Web Application, API, Network, and Infrastructure Security.
- Strong understanding of OWASP Top 10 and common vulnerability classes.
- Good knowledge of CVEs, CWEs, CVSS, and vulnerability risk assessment.
- Good understanding of networking fundamentals, including TCP/IP, DNS, HTTP/HTTPS, SSL/TLS, and common network protocols.
- Working knowledge of Windows and Linux operating systems.
- Hands-on experience with security tools such as Burp Suite, Nmap, Nessus/OpenVAS, Metasploit, Wireshark, OWASP ZAP, or equivalent.
- Ability to perform both tool-assisted and manual security testing.
- Good analytical and problem-solving skills.
- Strong technical documentation and report-writing skills.
- Good verbal and written communication skills.
- Ability to work independently and manage multiple security assessments effectively.
Posted Today