Assistant Manager - VAPT
BDO India · Pune, Maharashtra, India
BDO India · Pune, Maharashtra, India
**Role:** You will lead Vulnerability Management and Penetration Testing (VMPT) engagement track for Banking Industry, manage a team of security consultants, and deliver high-quality cybersecurity assessments for enterprise clients. **Responsibilities:** - Lead and mentor a team of cybersecurity consultants and analysts. - Allocate work, monitor project progress, and ensure timely delivery of engagements. - Review penetration testing reports and technical deliverables to maintain quality standards. - Coach junior team members through technical reviews, knowledge-sharing sessions, and hands-on mentoring - Serves as technical lead or subject matter specialist on Cyber Security Assessment projects covering either vulnerability assessment & penetration testing, network security architecture review, secure configuration/code review, firewall ruleset reviews - Experience with Vulnerability Management tools: Kali Linux, Acunetix, AppScan, Nexpose, Qualys Guard, Nessus, Nmap, Metasploit, Fortify, etc. - Manage day-to-day client relationships at mid and lower levels. - Good knowledge of TCP/ IP and Networks, including Firewalls, IDS/IPS, Routers, Switches, and network architecture. - Experience in Infrastructure Penetration Testing and Application Security Testing. - Demonstrates ability to work independently on projects with limited supervision and lead a small team with assistance from Manager. **Key Technical Skills:** - Hands-on experience performing Network, Web, API, Mobile, and Thick Client application security testing. - Proficient in using manual and automated application and network security tools such as Burp Suite, OWASP ZAP, Acunetix, ffuf, wfuzz, nikto, Nmap, and Nessus. - Experience in Secure Code Review. - Experience conducting Network Security Architecture Reviews and configuration reviews of Windows, Linux, UNIX, Solaris, Databases, etc. - Experience in basic scripting such as Shell, Python, PERL, etc. - Strong analytical and communication skills (written, verbal, and presentation - Open to learning new tools and technologies as per the project requirement - Interactive with team members and confident during client meetings under the guidance of senior members of the project - Be deadline-oriented and quality-focused - Certification: OSCP, OSCE, GPEN, CEH etc - Familiarity with industry standards and frameworks such as OWASP, CIS, and ISO27001 - Basic Knowledge of programming languages like C/C++, C#, JAVA, and ASP.NET, and familiarity with PERL/Python Scripting. - Basic Knowledge of the cloud environment and its various components. - Familiar with OWASP and Secure SDLC standards. - offensive security skill sets include backdoors, keyloggers, password dumpers, and spear phishing payloads. - Deliver Red Team Exercises and augment Senior Red Teamers. - Knowledge of standard security requirements within ASP.NET applications - Good Knowledge of TCP/IP, Network Security. - Ability to automate certain security test cases or write PoC using a scripting language (Python, Shell Script, Ruby/Perl, etc.) wherever required.