3 Vulnerability assessment Jobs in Mumbai | Vulnerability assessment Job openings in Mumbai
Apply to 3+ Vulnerability assessment Jobs in Mumbai on CutShort.io. Explore the latest Vulnerability assessment Job opportunities across top companies like Google, Amazon & Adobe.
Pune, Bengaluru (Bangalore), Noida, Hyderabad, Chennai, trivendam, Chandigarh, Kolkata, Mumbai · 5 - 8 years · ₹12L - ₹18L / yr · Bootstrapped · Posted 9 Sep 2026
Responsibilities
- Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
- Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
- Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
- Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
- Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
- Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
- Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
- Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
- Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
- Provide input into policies and standards related to application and cloud security controls.
Qualifications and Education Requirements
- Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
- 5-7 years of relevant experience in application security and/or vulnerability management.
- Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
- Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
- Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
- Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
- Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
- Excellent documentation, communication, and stakeholder engagement skills.
Desired Skills
- Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
- Experience using the ServiceNow platform for vulnerability or incident tracking.
- Proficiency in Azure cloud and Azure DevOps environments.
- Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.
Mumbai · 5 - 10 years · ₹12L - ₹15L / yr · Raised funding · Posted 13 Aug 2024
Summary:
● We are seeking a highly motivated and experienced Cyber security
● Expert to join our team. You will be responsible
for safeguarding our IT infrastructure, data, and applications from cyber threats.
● You will have a deep understanding of server, endpoint, mail, and infrastructure security and possess strong incident response skills.
● Additionally, you will be well-versed in relevant regulations and how to navigate them during data breaches.
Responsibilities:
● Implement and maintain comprehensive security controls for servers, endpoints, mail, and infrastructure.
● Conduct regular vulnerability assessments and penetration testing.
● Monitor security logs and SIEM systems for suspicious activity.
● Investigate and respond to security incidents, including data breaches.
● Develop and implement incident response plans and procedures.
● Stay up-to-date on the latest cyber threats and vulnerabilities.
● Provide security awareness training to employees.
● Advise on and implement security best practices throughout the organization.
● Understand and comply with relevant data privacy and security regulations (e.g., HIPAA, GDPR, PCI DSS).
● Work collaboratively with IT, business units, and legal teams.
NCR (Delhi | Gurgaon | Noida), Mumbai · 3 - 6 years · ₹8L - ₹14L / yr · Raised funding · Posted 7 Feb 2019


