← WorkMundi · 1M+ jobs from around the world, liveSign inCreate free account

VAPT Engineer

Soffit Infrastructure Services Pvt Ltd · Thrissur

📅 13/08/2026
🔔 Alert me about jobs like this
No password, no sign-up. Just the email — and you can leave the list anytime.
🔓 Apply — free →
Opens this job on WorkMundi. The account is free and takes under a minute.

See the other 113,540 jobs in India →

🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
Job Title: VAPT Engineer 3+ Years Experience Job Summary: We are looking for an experienced Vulnerability Assessment and Penetration Testing (VAPT) Engineer with 3+ years of experience in application and infrastructure security testing. The candidate will be responsible for identifying security vulnerabilities, performing penetration testing, preparing detailed reports, and supporting remediation activities. Key Responsibilities Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, mobile applications, and infrastructure. Conduct black-box, grey-box, and white-box security testing based on project requirements. Identify and validate vulnerabilities such as: o OWASP Top 10 o SQL Injection o Cross-Site Scripting (XSS) o Authentication and authorization issues o Broken access control o SSRF o CSRF o Security misconfiguration o API vulnerabilities o Business logic vulnerabilities Perform API security testing, including authentication, authorization, token validation, rate limiting, and API abuse scenarios. Conduct network and infrastructure VAPT, including server, network, firewall, and exposed services. Perform vulnerability scanning and manual validation using industry-standard tools. Analyze scan results and eliminate false positives through manual verification. Prepare detailed VAPT reports with vulnerability description, risk rating, evidence, business impact, and remediation recommendations. Work with development and infrastructure teams to support vulnerability remediation and retesting. Conduct security retesting to verify that identified vulnerabilities have been properly fixed. Maintain knowledge of emerging vulnerabilities, CVEs, attack techniques, and security best practices. Ensure testing activities comply with organizational security policies and applicable regulatory requirements. Required Technical Skills Minimum 3 years of experience in VAPT / Cybersecurity / Application Security. Strong knowledge of OWASP Web and API Security. Experience with tools such as: o Burp Suite o OWASP ZAP o Nmap o Nessus / Qualys o Metasploit o SQLMap o Postman Good understanding of: o HTTP/HTTPS o REST APIs o JWT/OAuth/OIDC o TCP/IP and networking o Linux and Windows o Web application architecture o Databases and SQL Ability to perform manual penetration testing, not just automated vulnerability scanning. Basic scripting knowledge in Python, PowerShell, Bash, or similar languages is desirable. Knowledge of cloud security, preferably Azure/Oracle Cloud/AWS, would be an advantage. Certifications Preferred CEH OSCP eJPT CompTIA Security+ CREST certifications Other recognized cybersecurity/VAPT certifications Educational Qualification Bachelors degree in Computer Science, Information Technology, Cybersecurity, or a related field. Compensation: Up to 800,000.00 per year Application Question(s): What is your current ctc What is your Expected ctc How many years of expereince Work Location: In person .
Read the rest of the job →
For people searching Engineer

144,883 engineer jobs are open right now

Here's how to pick the right one and stand out in your application.

144.883Jobs
31.687IN
81%EN

That number is real. WorkMundi's database shows 144,883 open engineer roles across the world. India has the most with 31,687 jobs, followed by the United States with 30,084. If you just finished reading one job ad and felt paralyzed by choice, you're not alone—but this scale is actually an advantage. It means you can afford to be selective.

Start by geography and language. The majority of engineer ads—117,837 of them—have the job posting text written in English. Use that as one filter, but remember: the ad text language tells you nothing about whether the role actually requires you to speak English day-to-day. Read the job description carefully. Then check which countries have the volume you're targeting. Singapore, Poland, and Australia round out the top five after India and the US.

Next, learn who's hiring. Accenture has posted 2,801 engineer roles. andurilindustries, speechify, and jobgether are also actively recruiting. If you're applying to one of these names, research their hiring patterns and interview style before you apply. That homework pays off.

When you interview, expect the question every engineer hears: 'Tell me about a time you had to debug a problem that wasn't in your job description.' Have a specific story ready—not a general one. Name the tools, the deadline pressure, and what you learned. Hiring managers listen for whether you see problem-solving as part of the role itself, not a favour.

👁 21 have read this
0 comments
Want to comment?

Leave your e-mail to comment, react and follow the posts for your role. It is free.

Similar jobs

Job on WorkMundi — the world's largest job board. See more jobs from every continent, updated live.

📢
🎁

Before you apply, rehearse this interview.

Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card.

I want my training →