Manager VA / VAPT

6 - 12 years

25 - 30 Lacs

Posted:11 hours ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

Manager VA / VAPT (Vulnerability Assessment & Penetration Testing)

**Location:*Mumbai

**Department:*Information Security

Role Overview

The Manager / Assistant Manager VA/VAPT will be responsible for overseeing the vulnerability assessment and penetration testing program across the organization. The role includes managing external vendors performing security testing, ensuring regulatory and internal policy compliance, handling day-to-day BAU activities, and preparing reports and dashboards for senior management and regulatory bodies.


Key Responsibilities

1. Vulnerability Management & Testing Oversight


  • Coordinate and manage end-to-end VA/VAPT activities conducted by external vendors.

  • Review and validate test scopes, methodologies, and deliverables.

  • Track remediation progress and coordinate with application/infrastructure teams for closure of findings.

  • Ensure testing frequency aligns with regulatory, internal, and client requirements.

  • Validate false positives and maintain quality of vulnerability reports.


2. Compliance & Regulatory Alignment


  • Ensure compliance with RBI, CERT-In, PCI-DSS, and other regulatory security testing mandates.

  • Maintain audit-ready evidence and documentation for all VA/VAPT-related activities.

  • Support internal and external audits (including from parent company, clients, and regulators).

  • Track and report on compliance posture related to vulnerability management.


3. Reporting & Metrics


  • Develop and maintain vulnerability management dashboards and reports for CISO and management.

  • Generate periodic risk summaries, trend analysis, and KPI/KRI reports.

  • Maintain trackers for testing schedule, remediation status, and exceptions.


4. Process & Governance


  • Define and continuously improve the VA/VAPT governance process, including scope definition, testing frequency, and remediation SLAs.

  • Manage change requests and deviations in coordination with vendors and internal teams.

  • Ensure adherence to secure SDLC principles and coordinate with DevSecOps initiatives.


5. Tools & Technical Proficiency


  • Utilize and manage tools such as Qualys, OpenText Fortify, WebInspect, and Burp Suite Professional for internal scans and validation.

  • Correlate and prioritize vulnerabilities based on criticality, exploitability, and asset sensitivity.

  • Support automation and integration of vulnerability data into enterprise dashboards or ticketing systems.


6. Stakeholder Management


  • Collaborate with IT, applications, cloud, and business teams to ensure timely risk mitigation.

  • Act as primary liaison with VA/PT vendors and ensure SLA adherence.

  • Present security posture updates to senior management and CISO.


Qualifications & Experience

Position

Experience Range

Educational Qualification

Certifications (Preferred)

Manager VA/VAPT

8 12 years total experience with 3+ years in vendor or team management

B.Tech / B.E. / M.Tech / MCA in Computer Science, IT, or related field

CEH, OSCP, CISSP, CISA, or equivalent

Key Skills & Competencies

  • Strong understanding of web, mobile, and infrastructure vulnerabilities and mitigation techniques.

  • Hands-on exposure to Qualys, Fortify, WebInspect, and Burp Suite Professional.

  • Familiarity with regulatory frameworks such as RBI, CERT-In, PCI-DSS, ISO 27001.

  • Strong analytical, documentation, and presentation skills.

  • Ability to handle multiple stakeholders and manage testing across multiple business lines.

  • Good understanding of secure SDLC and DevSecOps principles.


Soft Skills

  • Excellent communication and coordination skills.

  • Strong reporting and analytical mindset.

  • Ability to work under pressure and manage tight timelines.

  • Proven vendor and stakeholder management skills.


Key Responsibilities

1. Vulnerability Management & Testing Oversight


  • Coordinate and manage end-to-end VA/VAPT activities conducted by external vendors.

  • Review and validate test scopes, methodologies, and deliverables.

  • Track remediation progress and coordinate with application/infrastructure teams for closure of findings.

  • Ensure testing frequency aligns with regulatory, internal, and client requirements.

  • Validate false positives and maintain quality of vulnerability reports.


2. Compliance & Regulatory Alignment


  • Ensure compliance with RBI, CERT-In, PCI-DSS, and other regulatory security testing mandates.

  • Maintain audit-ready evidence and documentation for all VA/VAPT-related activities.

  • Support internal and external audits (including from parent company, clients, and regulators).

  • Track and report on compliance posture related to vulnerability management.


3. Reporting & Metrics


  • Develop and maintain vulnerability management dashboards and reports for CISO and management.

  • Generate periodic risk summaries, trend analysis, and KPI/KRI reports.

  • Maintain trackers for testing schedule, remediation status, and exceptions.


4. Process & Governance


  • Define and continuously improve the VA/VAPT governance process, including scope definition, testing frequency, and remediation SLAs.

  • Manage change requests and deviations in coordination with vendors and internal teams.

  • Ensure adherence to secure SDLC principles and coordinate with DevSecOps initiatives.


5. Tools & Technical Proficiency


  • Utilize and manage tools such as Qualys, OpenText Fortify, WebInspect, and Burp Suite Professional for internal scans and validation.

  • Correlate and prioritize vulnerabilities based on criticality, exploitability, and asset sensitivity.

  • Support automation and integration of vulnerability data into enterprise dashboards or ticketing systems.


6. Stakeholder Management


  • Collaborate with IT, applications, cloud, and business teams to ensure timely risk mitigation.

  • Act as primary liaison with VA/PT vendors and ensure SLA adherence.

  • Present security posture updates to senior management and CISO.

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
Crisil logo
Crisil

Financial Services

Mumbai Maharashtra

RecommendedJobs for You

hyderabad, bengaluru, delhi / ncr