Search by job, company or skills

Security Engineer Vulnerability Management & VAPT

  • Posted 7 hours ago
  • Be among the first 10 applicants

Job Description


Role:

  • We're looking for a hands-on security engineer to support the external attack surface management and crowdsourced security programmes.
  • This role sits between offensive security and enterprise vulnerability management.
  • You'll manually validate vulnerabilities affecting externally exposed applications and systems—including findings submitted by security researchers—and stay involved through risk assessment, remediation and retesting.
  • If you enjoy understanding whether a vulnerability is genuinely exploitable rather than simply reviewing scanner results, this could be a strong fit.

Responsibilities:

  • Investigate vulnerabilities affecting externally exposed applications, infrastructure and services.
  • Manually reproduce reported vulnerabilities and determine their real-world exploitability.
  • Perform vulnerability assessment and penetration testing using tools such as Burp Suite, Nmap, cURL or equivalent security tools.
  • Conduct reconnaissance, service fingerprinting and hands-on web/application security testing.
  • Prioritise vulnerabilities based on exploitability, exposure, severity and potential business impact.
  • Validate findings submitted through crowdsourced security and vulnerability disclosure programmes.
  • Work with application, infrastructure and security teams to explain findings and agree practical remediation actions.
  • Track vulnerabilities through remediation and independently verify that fixes have resolved the issue.
  • Monitor vulnerability trends, outstanding findings and remediation progress.

Required Skills:

  • Relevant experience from areas such as vulnerability management, vulnerability assessment & penetration testing (VAPT), application security/appSec, penetration testing, offensive security, product security, and attack surface management.
  • Security certifications such as OSCP, eJPT, CISSP, GSEC, Security+ or CEH are preferred.
  • The key requirement is demonstrated experience personally investigating and validating security vulnerabilities.
  • Hands-on vulnerability assessment and security testing and using tools such as Burp Suite, Nmap, cURL or comparable tools.
  • Manually reproducing vulnerabilities and confirming whether reported issues are exploitable.
  • Working with application and infrastructure teams to move vulnerabilities from identification through remediation and retesting.
  • Experience testing web applications, APIs or externally exposed services will be particularly relevant.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 152483731

Beware of Scammers

We don’t charge money for job offers