VAPT Security Engineer
Alignity Consulting · Shaikpet, Telangana, India · On-site
Posted Sep 23, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Do you love a career where you Experience, Grow & Contribute at the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you. Learn how we are redefining the meaning of work, and be a part of the team raved by Clients, Job-seekers and Employees. Jobseeker Video Testimonials Employee Glassdoor Reviews If you are a Penetration Testing Senior Consultant looking for excitement, challenge and stability in your work, then you would be glad to come across this page. We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details. Check if you are up for maximizing your earning/growth potential, leveraging our Disruptive Talent Solution. Role:Penetration Testing Senior Consultant Location: Hyderabad | Bengaluru | Pune | Chennai | Kolkata Experience:3-5 Years Work Mode: Hybrid Type: Contract to Hire Notice Period:Immediate Joiners Requirements As a Penetration Testing Senior Consultant, you will lead the execution of offensive security engagements and help clients identify, validate, and remediate security vulnerabilities across their digital ecosystem. You will work across application, API, mobile, thick-client, network, cloud, and enterprise infrastructure environments while collaborating with technical and business stakeholders to translate security findings into actionable business risk and remediation recommendations. Key Responsibilities Lead penetration testing workstreams across web applications, APIs, mobile, thick-client, network, cloud, and infrastructure environments. Design test plans and execute manual and automated security assessments. Identify, validate, exploit, and document security vulnerabilities. Perform manual testing for vulnerabilities including: SQL Injection / Blind SQL Injection XSS and CSRF XXE SSRF Insecure Deserialization HTTP Request Smuggling Authentication & Authorization weaknesses Business Logic vulnerabilities Assess OAuth 2.0, OpenID Connect, session management, identity, and access controls. Conduct secure code reviews using OWASP Secure Coding Practices or comparable methodologies. Perform application security architecture reviews and threat modeling. Conduct vulnerability assessments across application, infrastructure, cloud, mobile, and enterprise environments. Use industry-standard security testing tools such as Burp Suite, Fiddler, Wireshark, Nmap, Metasploit, Nessus, Qualys, Tenable, Veracode, Frida, Apktool, JADX, dnSpy, and IDA Pro. Develop scripts and automation using Python, PowerShell, Bash, or similar technologies to improve reconnaissance, testing, evidence collection, and reporting. Support purple team, red team, adversarial simulation, and threat-informed testing activities. Map attack scenarios and findings to MITRE ATT&CK and relevant threat behaviors. Coordinate with application, infrastructure, cloud, development, and security operations teams for remediation and…