Job Description
EXECUTIVE SUMMARY
Cybervol seeks an experienced and technically proficient VAPT Analyst to join our Offensive Security team. Responsible for conducting comprehensive vulnerability assessments and penetration tests across our clients IT infrastructure, applications and networks.
This is a hands on technical role requiring deep expertise in offensive security tools, techniques and methodologies. The successful candidate will combine technical excellence with the ability to communicate complex findings clearly to both technical and executive stakeholders.
CORE RESPONSIBILITIES
• Design and execute comprehensive penetration tests on systems, networks, applications, APIs, and web platforms
• Conduct structured red team exercises to test detection and response mechanisms
• Combine automated scanning (Nessus, Qualys, OpenVAS) with advanced manual testing techniques
• Identify, exploit, and document vulnerabilities with proof-of-concept (PoC) demonstrating real-world impact
• Perform privilege escalation, lateral movement, and post-exploitation simulations
• Emulate advanced persistent threat (APT) tactics using MITRE ATT&CK framework
• Test web applications (OWASP Top 10) using Burp Suite Pro and custom scripts
• Execute network penetration tests targeting firewalls (Checkpoint, ASA), routers, switches, and internal services
• Conduct regular vulnerability scans across infrastructure, endpoints, cloud environments, and applications
• Validate findings, triage false positives, and assign CVSS v3.1 risk ratings
• Prioritise remediation based on exploitability, business impact, and compliance implications
• Track remediation progress and conduct re-assessments to verify closure
• Prepare detailed technical reports documenting methodology, findings, evidence, and recommendations
• Produce executive summaries translating technical findings into business risk language
• Present findings to technical and management stakeholders; facilitate remediation planning
• Assess detection gaps and coordinate findings with blue team and security operations
EXPERIENCE & QUALIFICATIONS
• B.Sc in Computer Science, IT, Cybersecurity or equivalent experience
• 3+ years hands-on experience with focus on penetration testing, red team activities, and vulnerability
assessment
• Proficiency in Burp Suite Pro, Nessus, Metasploit, Nmap, OWASP ZAP, Wireshark
• Network knowledge: TCP/IP, firewalls (Checkpoint or ASA), routers, switches, VPNs
• Systems expertise: Windows & Linux, Active Directory privilege escalation
• Cloud experience: AWS or Azure; GCP, container security, IAM assessments desired
• Web security: OWASP Top 10, APIs, business logic testing; exploit development desired
• Operations awareness: SIEM platforms, EDR tools, incident response
• Required Certification: CEH or eWPT nn
• Optional Certifications: OSCP, GCIH, CRTO
• Demonstrated experience planning and executing end-to-end VAPT engagements across
infrastructure, applications, and networks