Technical Lead-Cybersecurity
Birlasoft
Birlasoft
Seeking a seasoned Vulnerability Assessment and Penetration Testing (VAPT) Specialist to lead efforts in identifying, assessing, and validating security vulnerabilities. This role is crucial for enhancing our cybersecurity posture across diverse environments including applications, networks, cloud, infrastructure, and enterprise systems. Responsibilities encompass leading VAPT engagements, security reviews, risk analysis, and remediation validation.
This position requires a proactive approach to safeguarding organizational assets and maintaining robust security defenses. The ideal candidate will possess a deep understanding of current threat landscapes and the ability to translate technical findings into actionable security improvements.
Perform comprehensive Vulnerability Assessments and Penetration Testing on web applications, APIs, mobile apps, servers, databases, cloud environments, and network infrastructure. Conduct authenticated and unauthenticated scans, validating findings through manual testing and executing internal/external penetration tests. Align assessments with OWASP Top 10, MITRE ATT&CK, and industry best practices.
Analyze vulnerabilities, assess business impact, assign risk ratings, and provide clear remediation recommendations. Validate remediation efforts through re-testing. Prepare detailed technical reports, executive summaries, and risk assessment documentation. Collaborate with infrastructure, application development, cloud, and security teams to drive remediation. Support security audits, compliance, and regulatory requirements.
Monitor emerging threats and attack techniques to refine assessment methodologies. Develop testing methodologies, standards, SOPs, and operational runbooks. Support Red Team, Purple Team, and Security Operations. Participate in security architecture reviews and offer secure design recommendations.
Expertise in core technical skills including Web Application, Network, API, Infrastructure, and Cloud Security Testing. Proficient in Secure Configuration Reviews, Threat Modeling, Risk Assessment & Analysis, and Remediation Validation. Familiarity with SAST and DAST tools.
Strong understanding of security frameworks and methodologies such as OWASP Top 10, OWASP ASVS, OWASP API Security Top 10, MITRE ATT&CK, SANS Security Controls, NIST Cybersecurity Framework, CVSS Risk Scoring, and CIS Benchmarks is essential.
This role requires extensive experience in VAPT and a proven track record of identifying and mitigating complex security vulnerabilities. A proactive mindset and excellent communication skills are vital for collaborating with cross-functional teams and presenting findings to stakeholders.
Birlasoft
IT Consulting