VAPT Lead
On-siteChennai, Tamil Nadu, India
Job Summary
Conduct scheduled and ad-hoc vulnerability scans on server farms and endpoints using Tenable Nessus and Qualys. Analyze results to identify false positives, prioritize risks via CVSS scores, and track the lifecycle of open vulnerabilities from discovery to closure. Act as the primary point of contact for clients, explaining remediation steps and negotiating downtime for patching windows. Prepare technical reports for engineering teams and executive dashboards highlighting risk trends. Perform configuration compliance scanning against CIS Benchmarks for hardening standards. Requires 5-6 years of experience with strong communication skills.
Required Qualifications
- 5-6 years of experience
- Strong communicator
- Deep expertise in Tenable Nessus (Tenable.sc / Tenable.io) and Qualys VM
- Strong administration knowledge of Windows Server (Active Directory, Registry, Group Policy) and Linux (RHEL/Ubuntu/CentOS)
- Familiarity with Nmap, Burp Suite (for basic web validation), and Metasploit (for verifying exploitability)
- Basic proficiency in Python, Bash, or PowerShell
- Excellent verbal communication for client stakeholder management
Desired Qualifications
- Experience with AWS or Azure native security tools (Inspector, Defender for Cloud)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.