Home / Careers / VAPT Engineer
Offensive Security

VAPT Engineer

Offensive Security · Senior · Remote · Full-time

Lead manual, exploit-driven penetration testing across web, API, network, and cloud targets. You will go far beyond scanners, chain real flaws into business impact, and set the technical bar for every finding we ship.

What you will do

  • Scope and deliver penetration tests across web applications, APIs, internal and external networks, and cloud
  • Manually exploit and chain vulnerabilities to prove genuine, demonstrable business impact
  • Develop and adapt exploits, payloads, and tooling when off-the-shelf options fall short
  • Write clear, prioritized reports engineers can act on and leaders can understand
  • Brief clients on findings and support them through remediation and verified retest
  • Mentor junior testers and raise the bar on internal methodology and tooling

What we are looking for

  • 4+ years of hands-on penetration testing across web, API, network, and at least one major cloud
  • OSCP required; OSWE, OSEP, or CRTO a strong plus and expected within the first year
  • Deep, manual command of the OWASP Top 10, API and auth flaws, and SSRF/deserialization/injection chains
  • Proven exploit development or modification skills and fluency in Python and at least one of Bash, Go, or PowerShell
  • Strong cloud attack knowledge in AWS, Azure, or GCP, including IAM and metadata abuse
  • Exceptional technical writing - your reports are the product, not the scan output

Nice to have

  • Mobile, thick-client, or container and Kubernetes security specialization
  • Published CVEs, research, tooling, or conference talks
  • Burp Suite extension or custom tooling development
Get ahead of zero

Ready to see yourself the way an adversary would?

Book a scoped assessment - we will map what is reachable, prove what is exploitable, and give you a ranked path to closing it before someone finds it first.

Book a free scoping call