Website:
cysigil.com
Job details:
Company: Cysigil
Location: Bengaluru, India — On-site
Employment type: Full-time
Experience: 0–2 years
Function: Offensive Security / Vulnerability Assessment & Penetration Testing
Reports to: Lead Security Consultant — VAPT
About the role
Cysigil delivers vulnerability assessment and penetration testing engagements across web applications, APIs, networks, mobile apps and cloud environments for clients in BFSI, healthcare, SaaS and manufacturing.
We are hiring an Associate Security Analyst to join the VAPT practice. This is a hands-on, delivery-facing role.
What you'll do
- Test web applications, APIs, and internal/external networks — assessment through exploitation
- Run recon and enumeration that goes past the obvious attack surface
- Work in Burp Suite, Nmap, OWASP ZAP, Nikto and Kali
- Support compliance-driven testing against OWASP Top 10
- Stay current on CVEs, threats and techniques.
- Conduct manual and automated testing aligned to OWASP Top 10, OWASP API Security Top 10, and OWASP MASVS/MSTG.
- Identify, exploit, and validate common vulnerabilities (SQLi, XSS, CSRF, IDOR/BOLA, authentication/authorization flaws, business logic issues).
- Document findings with clear reproduction steps, evidence/PoC, severity ratings (CVSS), and remediation guidance.
- Retest and verify closed vulnerabilities
What you need
- Foundational knowledge of the OWASP Top 10 (Web, API, Mobile) and common attack techniques.
- Familiarity with tools such as Burp Suite, OWASP ZAP, Nmap, and mobile analysis frameworks.
- Basic scripting ability (Python/Bash) for automation.
- Understanding of networking, HTTP, TLS, and authentication mechanisms.
- Strong analytical, documentation, and reporting skills.
Good to have
Cryptography fundamentals. CTF placements. CEH, eJPT, Security+. A HackTheBox or TryHackMe profile. Bug bounty acknowledgements. CVEs.
What you get
Live client work from the start. Exposure across VAPT, red teaming, cloud security and GRC. Compensation that follows demonstrated skill.
Apply
CV to careers@cysigil.com,
subject "Associate Security Analyst — VAPT". Attach a write-up, a profile, a disclosure — anything you've done. We read that before the CV.
Click on Apply to know more.