Technical Lead-Cybersecurity
Birlasoft Limited Noida, Uttar Pradesh, India
IT Services and IT Consulting · 10,001+ employees
About the role
The Technical Lead will perform comprehensive vulnerability assessments and penetration testing across web, mobile, cloud, and network infrastructure. They will also lead remediation efforts, validate security findings, and provide technical guidance to cross-functional teams.
What they look for
Requirements
Candidates must possess extensive experience in vulnerability management, penetration testing methodologies, and security frameworks like OWASP and MITRE ATT&CK. Strong analytical skills are required to assess business impact, manage risk, and drive secure design recommendations.
Full description
Area(s) of responsibility
Role Summary
We are seeking an experienced Vulnerability Assessment and Penetration Testing (VAPT) Specialist responsible for identifying, assessing, and validating security vulnerabilities across applications, networks, cloud environments, infrastructure, APIs, and enterprise systems. The candidate will lead vulnerability assessments, penetration testing engagements, security reviews, risk analysis, and remediation validation activities to strengthen the organization's cybersecurity posture.
Key Responsibilities
- Perform Vulnerability Assessments and Penetration Testing across web applications, APIs, mobile applications, servers, databases, cloud environments, and network infrastructure.
- Conduct authenticated and unauthenticated vulnerability scans and validate findings through manual testing.
- Execute internal and external penetration testing exercises to identify security weaknesses and exploitation paths.
- Perform security assessments aligned to OWASP Top 10, MITRE ATT&CK, and industry best practices.
- Assess cloud environments for security misconfigurations, excessive permissions, exposed assets, and compliance gaps.
- Conduct source code security reviews and secure configuration assessments where applicable.
- Analyze vulnerabilities, determine business impact, assign risk ratings, and provide remediation recommendations.
- Validate remediation activities and perform re-testing of vulnerabilities.
- Prepare detailed technical reports, executive summaries, and risk assessment documentation.
- Work closely with infrastructure, application development, cloud, and security teams to drive remediation efforts.
- Support security audits, compliance assessments, and regulatory requirements.
- Monitor emerging threats, vulnerabilities, and attack techniques to improve assessment methodologies.
- Develop testing methodologies, assessment standards, SOPs, and operational runbooks.
- Support Red Team, Purple Team, and Security Operations initiatives when required.
- Participate in security architecture reviews and provide secure design recommendations.
Required Skills
Core Technical Skills
- Web Application Penetration Testing
- Network Penetration Testing
- API Security Testing
- Infrastructure Security Assessment
- Cloud Security Assessment
- Secure Configuration Reviews
- Threat Modeling
- Risk Assessment & Analysis
- Remediation Validation
- SAST,DAST
Security Frameworks & Methodologies
- OWASP Top 10
- OWASP ASVS
- OWASP API Security Top 10
- MITRE ATT&CK
- SANS Security Controls
- NIST Cybersecurity Framework
- CVSS Risk Scoring
- CIS Benchmarks
Similar roles
-
Staff Security Engineer
Robots and Pencils United States · $116K–$160K/yr
-
Cybersecurity Awareness Volunteer
CyberUp St. Louis, Missouri, United States
-
Senior Security Engineer
Latitude IT Solutions $119K–$137K/yr
-
Security Engineer
Latitude IT Solutions $102K–$118K/yr
-
2027 Internal Audit - Information Technology & Cybersecurity Summer Internship
Brown Brothers Harriman New York, New York, United States · $52K/yr
-
Security Engineer III - Network and Cloud Security - Hybrid (Remote Considered) - 26-103
PriMed Management Consulting Services, Inc. San Ramon, California, United States · $109K–$144K/yr