Security Analyst – VAPT & Penetration Testing
The candidate will be responsible for conducting comprehensive Vulnerability Assessment and Penetration Testing (VAPT) across enterprise IT environments, applications, networks, infrastructure, cloud platforms and security systems.
Key Responsibilities
- Conduct internal and external penetration testing across networks, servers, firewalls, endpoints and infrastructure.
- Perform web application and API penetration testing, including testing against OWASP vulnerabilities.
- Conduct vulnerability assessments and manually validate identified vulnerabilities and false positives.
- Perform controlled exploitation to determine the actual impact and severity of identified security weaknesses.
- Conduct security testing of network devices, firewalls, routers, switches, VPNs, load balancers and servers.
- Perform application security testing covering authentication, authorization, session management, input validation, encryption and business-logic vulnerabilities.
- Conduct source-code security reviews and support SAST/DAST activities.
- Assess security of cloud environments and operating systems.
- Perform security assessments using tools such as Burp Suite, Nmap, Nessus, Metasploit, Wireshark and Kali Linux.
- Develop or automate penetration-testing/security activities using Python.
- Prepare detailed penetration-testing and vulnerability-assessment reports containing evidence, risk ratings, business impact and remediation recommendations.
- Work with technical teams to remediate identified vulnerabilities.
- Conduct retesting and validation after remediation.
- Follow established penetration-testing methodologies and cybersecurity best practices.
- Support security teams in identifying attack vectors and improving the organization’s overall security posture.
Required Technical Skills
Strong hands-on knowledge of:
- Vulnerability Assessment & Penetration Testing (VAPT)
- Network Penetration Testing
- Web Application Penetration Testing
- API Security Testing
- Infrastructure Security Testing
- Cloud Security Testing
- Vulnerability Exploitation & Validation
- OWASP Top 10
- SAST & DAST
- Source-Code Security Analysis
- Secure Coding Practices
- Network & Operating System Security
- Python/Security Automation
- Burp Suite
- Nmap
- Nessus
- Metasploit
- Wireshark
- Kali Linux
Requirements
Standards / Framework Knowledge
The candidate should have good knowledge of relevant cybersecurity standards and methodologies, including:
- OWASP
- NIST
- ISO/IEC 27001
- PCI DSS
- Penetration-testing methodologies and security best practices
Life at BAE Systems
Within a growing network of around 100,000 colleagues in more than 40 countries, our teams bring together people with diverse skills, ways of thinking and backgrounds - while our work spans the depths of the ocean to the far reaches of space.
Tackling complex problems. Building innovative solutions. This is a place where you can make real change happen, for your career and the world.
Discover more
Inclusion
We want everyone here to feel valued and empowered to thrive. Who you are should never define what you can do. We believe when you bring together different people and perspectives it inspires creativity and drives innovation, helping us fulfil our purpose and is integral to our culture. Everyone is heard and respected here.
Learn more
Learning and development
If you’re curious, hungry for more responsibility, and prepared to step out of your comfort zone, there are endless opportunities to grow with us. At every stage of your career our first-class training, coaching and development programmes, role models and mentors will help you embrace your potential and take the next step.
Learn more
Rewards and benefits
Great work deserves benefits that go beyond your salary. Whether it’s health, wellbeing, or financial security for you and your family – our flexible benefits help you focus on what’s important to you.
Learn more
Making an impact
Together we embrace every opportunity to have a positive impact. On the world around us, our communities, and each other.
Learn more