
VAPT Consultant (Vulnerability Assessment & Penetration Testing)
Tec4 Advisory India Private Limited • Delhi, India
**Role & seniority: ** Offensive Security / VAPT (2–6 years), Full-time; Cybersecurity – Offensive Security
**Location & work type: ** Delhi NCR (Hybrid)
**Stack/tools: **
-
Web/API: Burp Suite
-
Scanning/enum: Nmap, Nuclei
-
Exploitation: Metasploit
-
Vuln platforms: Nessus / Qualys
-
Mobile: MobSF, Frida
-
Network: Wireshark
-
Scripting/automation: Python, Bash, PowerShell
-
OS/infra: Linux/Windows, Active Directory
**Top 3 responsibilities: **
-
Perform manual VAPT across web, API, mobile, network, and cloud (not only automated scanning)
-
Validate and chain vulnerabilities with proof of concept to show business impact
-
Produce risk-rated technical + executive reports and ensure findings are retested/closed
**Must-have skills: **
-
2–6 years hands-on penetration testing / VAPT
-
Strong understanding of web/API/mobile/network attack techniques
-
Linux/Windows, Active Directory, common network protocols
-
Scripting (Python/Bash/PowerShell)
-
Strong report writing ability
**Nice-to-haves: **
-
Red teaming, attack surface management, and compliance-driven testing (e.g., CERT-In, RBI, SEBI)
-
Ability to keep methodologies current and deliverables through QRM review on time
Full Description
Department Cybersecurity – Offensive Security Location Delhi NCR (Hybrid) Experience 2–6 years in VAPT / Offensive Security Employment Type Full-time Key Expectations
-
Perform manual VAPT across web, API, mobile, network and cloud environments, going beyond automated scans
-
Validate and chain vulnerabilities to demonstrate real business impact with proof of concept
-
Deliver clear, risk-rated technical and executive reports with practical remediation guidance
-
Conduct retests and work with client teams until findings are verified as closed
-
Support red teaming, attack surface management and compliance-driven testing (CERT-In, RBI, SEBI)
-
Keep methodologies current and ensure deliverables pass QRM review on time
Key Requirements
-
Bachelor's degree in Computer Science, IT, Engineering or a related field
-
2–6 years of hands-on experience in VAPT / penetration testing
-
Proficiency with tools such as Burp Suite, Nmap, Metasploit, Nessus / Qualys, Nuclei, MobSF, Frida and Wireshark
-
Strong understanding of web, API, mobile and network attack techniques
-
Working knowledge of Linux and Windows environments, Active Directory and common network protocols
-
Scripting ability in Python, Bash or PowerShell
-
Strong report-writing skills