Cybersecurity Consultant – VAPT & Red Teaming
SARC
New Delhi, Delhi, India
Full-Time
Posted Today
New Delhi, Delhi, India
Full-Time
Posted Today
Job Description & Responsibilities
Cybersecurity Consultant – VAPT & Red Teaming
Experience - 3 to 5 years
About the Role
We are looking for a passionate and experienced Cybersecurity Consultant to join our team. The ideal candidate should have strong hands-on expertise in offensive security, vulnerability assessments, penetration testing, and red teaming. If you thrive in challenging security environments and enjoy solving complex security problems, we would love to connect with you.
Key Responsibilities
- Conduct Vulnerability Assessment & Penetration Testing (VAPT) across web applications, APIs, networks, infrastructure, and external attack surfaces.
- Perform web application security assessments, including authentication, authorization, session management, input validation, and business logic testing.
- Conduct API penetration testing covering REST, SOAP, GraphQL, authentication mechanisms, access controls, and data exposure.
- Execute infrastructure VAPT across servers, network devices, firewalls, cloud environments, and enterprise infrastructure.
- Participate in red teaming and adversary simulation engagements, including reconnaissance, attack-path identification, exploitation, and post-exploitation activities.
- Perform authorized post-exploitation activities to assess the impact of identified vulnerabilities and demonstrate potential business risks.
- Conduct lateral movement assessments to identify opportunities for unauthorized access across systems, network segments, and enterprise environments.
- Identify, analyze, validate, and responsibly document security vulnerabilities, including proof of concept and supporting evidence.
- Prepare detailed technical reports covering findings, severity, business impact, attack paths, remediation recommendations, and revalidation results.
- Collaborate with clients and internal teams to communicate technical findings and provide actionable security improvement recommendations.
- Stay updated on emerging vulnerabilities, exploitation techniques, attack frameworks, and industry security practices.
Required Skills & Experience
- 3–5 years of hands-on experience in VAPT, offensive security, cybersecurity consulting, or a related field.
- Strong practical experience in web application, API, and infrastructure penetration testing.
- Good understanding of networking and security concepts, including TCP/IP, DNS, HTTP/HTTPS, authentication, firewalls, and network segmentation.
- Hands-on experience with reconnaissance, vulnerability identification, exploitation, post-exploitation, and lateral movement techniques in authorized assessment environments.
- Familiarity with tools such as Burp Suite, Nmap, Metasploit, Nuclei, BloodHound, Impacket, and relevant red teaming frameworks.
- Working knowledge of OWASP Top 10, OWASP API Security Top 10, and common vulnerability classification standards such as CVSS and CWE.
- Ability to analyze complex security issues, develop attack scenarios, and provide practical remediation guidance.
- Strong technical documentation, communication, and client-facing skills.
- Ability to work independently and collaboratively across multiple security engagements.
Preferred Certifications
- OSCP
- CRTP
- CRTO or other recognized red teaming certifications
- CREST or equivalent offensive security certifications
What We Offer
- Exposure to diverse cybersecurity consulting and offensive security engagements.
- Opportunities to work on challenging VAPT, red teaming, and security assessment projects.
- A collaborative environment focused on continuous learning and professional growth.*
About SARC
Job Details
Employment TypeFull-Time
Work ModeOn-Site
Experience3 – 5 years
Positions1
Posted by
N/A
Posted on:
17 Sept 2026
About SARC
More open roles
- Seeking Android Application Development Tutor in Wadala JalandharUrbanPro.com · Punjab, India
- Full-Stack Engineer - Node.js / NestJS / React / TypeScript | Multi-Tenant B2B SaaS (3-5 YOE)Script Assist · Ahmedabad, Gujarat, India
- Senior Cloud Infrastructure Engineer (Azure)Numerator · India
- GCP Cloud Engineer - VOISVodafone · India
- SDE 3 (Senior Software Engineer)Weekday AI (YC W21) · New Delhi, Delhi, India
- Software Engineer / Software DeveloperEroNkan Technologies · Ahmedabad, Gujarat, India