Job Summary
Job Summary : Job Title: Vulnerability Management & Penetration Testing Specialist (with CSPM) Department: Information Security / Cyber Security Experience Level: Mid–Senior (3–6+ Years) Location: Role Overview We are seeking an experienced Vulnerability Management (VM) & Penetration Testing Specialist to lead end-to-end vulnerability assessments, dynamic application scanning, and penetration testing across on-premises and cloud environments. In this role, you will be responsible for managing enterprise VM tooling, executing Web Application Security (WAS) scans, validating vulnerabilities through manual penetration testing, and securing multi-cloud posture via Cloud Security Posture Management (CSPM).
Key Responsibilities
Job Responsibilities : End-to-End Vulnerability Management: ○ Deploy, configure, and maintain enterprise Vulnerability Management platforms (e.g., Qualys or similar). ○ Manage scan schedules, credentialed scanning, asset discovery, and target grouping across hybrid infrastructure. ○ Triage, prioritize, and track vulnerabilities from identification through to remediation and re-validation. ● Web Application Scanning (WAS): ○ Configure and execute automated dynamic application security scans (DAST/WAS) for web applications and APIs. ○ Analyze scan findings, eliminate false positives, and deliver clear remediation steps to application owners. ● Penetration Testing & Validation: ○ Perform network, infrastructure, and web application penetration testing based on OWASP Top 10, NIST, and PTES standards. ○ Manually validate critical scanner findings via exploit verification and proof-of-concept testing. ○ Deliver comprehensive assessment reports detailing business impact, risk ratings, and actionable remediation guidance. ● Cloud Security Posture Management (CSPM): ○ Monitor and manage CSPM tooling (e.g., Wiz, AWS Security Hub). ○ Identify cloud misconfigurations, IAM risks, compliance drifts, and unmanaged exposure across multi-cloud environments. ○ Collaborate with Cloud and DevOps teams to enforce security guardrails and remediation playbooks.
Skill Requirements
Skill Requirement : Core Technical Expertise: ○ Proven hands-on experience running enterprise VM tools end-to-end (Qualys VMDR). ○ Deep understanding of web application vulnerabilities (SQLi, XSS, SSRF, IDOR, authentication flaws) and automated WAS tools. ○ Solid background in manual penetration testing for web apps, APIs, and network systems (using tools like Burp Suite Professional, Metasploit, Nmap). ○ Practical knowledge of major cloud platforms (AWS/Azure/GCP) and hands-on exposure to CSPM solutions. ○ Strong grasp of vulnerability scoring systems (CVSS v3/v4), CWE, CVE, and compliance benchmarks (CIS, ISO 27001). ● Preferred Certifications: ○ Penetration Testing: OSCP, eWPT / eCPPT, CEH (Practical), GPEN. ○ Vulnerability & Cloud Security: Qualys Certified Specialist, Tenable Certified, AWS Certified Security - Specialty, or CCSP.