About the role
G-Info Technology Solutions Private Limited (GISPL) is a CERT-In Empanelled Information Security Auditing Organization providing cybersecurity assessment, VAPT, security testing and compliance-focused security services to organisations across industries.
Our engagements span Web Applications, Mobile Applications, APIs, Network & Infrastructure, Cloud, Source Code, Backend Systems and other security assessments, with exposure to enterprise and regulated environments.
We are expanding our cybersecurity team and are looking for people at different stages of their cybersecurity journey. This opportunity is not restricted to one experience level.
Open positions: Trainee, Junior Consultant, Consultant, Senior Consultant and Team Lead.
Whether you are:
- A fresher looking to start your career in cybersecurity
- A trainee with lab/CTF experience
- A junior penetration tester
- An experienced VAPT consultant
- A senior security tester
Or someone capable of independently leading VAPT engagements and teams
We would like to hear from you.
Trainee / Fresher
You could be suitable if you have:
- Basic understanding of networking
- Linux fundamentals
- Basic cybersecurity concepts
- Familiarity with OWASP
- Hands-on experience with Kali Linux
- CTF/lab experience
- TryHackMe / Hack The Box / PortSwigger experience
- Basic scripting knowledge
Professional experience is not mandatory.
Junior Security Tester (0–2 years)
Expected to have some hands-on experience with:
- Nmap
- Burp Suite
- Nessus/Qualys
- Linux
- Web application testing
- Basic API testing
- Vulnerability validation
- Basic report preparation
VAPT Consultant (2–5 years)
Expected to independently perform assessments across areas such as:
- Web
- API
- Network
- Infrastructure
- Mobile
- Cloud
Strong understanding of vulnerability validation, exploitation, reporting and remediation is expected.
Senior Consultant / Team Lead (5+ years)
Expected to demonstrate:
- Independent ownership of VAPT engagements
- Advanced web/API/network testing
- Manual exploitation capability
- Client interaction
- Report review
- Team mentoring
- Assessment planning
- Quality assurance
- Project/task management
Leadership capability and the ability to review another tester's work will be important.
What we’re looking for
Relevant certifications include:
- CEH
- OSCP
- eJPT
- PNPT
- CRTP
- Security+
- CREST certifications
- Cloud security certifications
Candidates without certifications but with demonstrable practical skills are also encouraged to apply.
Tools and technologies. Depending on your level, exposure to the following is useful:
- Burp Suite
- Nmap
- Nessus
- Qualys
- Metasploit
- Wireshark
- Kali Linux
- OWASP ZAP
- BloodHound
- SQLMap
- Nikto
- Gobuster
- Postman
- Android/iOS security tools
- AWS/Azure security tools
You do not need to know every tool listed above.
Certifications
- OSCP
- CEH
- eJPT
- PNPT
- CRTP
- Security+
- CREST
Benefits
Work with a CERT-In Empanelled security auditing organization
Exposure to real-world security assessments
Work across Web, Mobile, API, Network, Cloud and other technologies
Opportunity to work with enterprise and regulated-sector customers
Exposure to compliance-driven security assessments
Structured growth from Trainee to Consultant to Senior Consultant to Team Lead
Opportunity to develop both technical and client-facing skills



