Track This Job
Add this job to your tracking list to:
- Monitor application status and updates
- Change status (Applied, Interview, Offer, etc.)
- Add personal notes and comments
- Set reminders for follow-ups
- Track your entire application journey
Save This Job
Add this job to your saved collection to:
- Access easily from your saved jobs dashboard
- Review job details later without searching again
- Compare with other saved opportunities
- Keep a collection of interesting positions
- Receive notifications about saved jobs before they expire
AI-Powered Job Summary
Get a concise overview of key job requirements, responsibilities, and qualifications in seconds.
Pro Tip: Use this feature to quickly decide if a job matches your skills before reading the full description.
Employment Type: Full-time
Job Description
We are looking for a Cybersecurity Consultant who will execute and deliver cybersecurity assessments and adversarial simulation exercises. The consultant will work closely with project and technical teams to uncover vulnerabilities, assess risks, and help clients strengthen their cyber resilience.
Key Responsibilities
- Conduct Vulnerability Assessment and Penetration Testing (VAPT) across web, mobile, API, network, wireless, RF, and cloud environments for both government and private sector clients.
- Perform Source Code Review (SCR) and Software Composition Analysis (SCA) to identify vulnerabilities in custom and open-source components.
- Execute Host Configuration Reviews (HCR) to ensure compliance with hardening baselines and industry best practices.
- Conduct Adversarial Simulations, including Red Teaming and Purple Teaming exercises, to evaluate detection, response, and defense capabilities.
- Assess and communicate risk using frameworks such as CVSS 3.1 / 4.0 and 5×5 likelihood–impact risk matrices.
- Prepare and deliver professional, actionable reports with clear technical findings and concise executive summaries.
- Support the sales team in technical meetings, scoping discussions, and client presentations.
Minimum 1 to 3 years of hands-on experience in cybersecurity consulting, penetration testing, or related offensive security operations.
Technical Qualifications
- Practical experience in penetration testing, red teaming, or offensive security operations.
- Strong understanding of network infrastructure, web services, mobile, source code, and cloud security vulnerabilities and exploitation techniques.
- Hands-on experience with security tools such as Burp Suite, Metasploit, Kali Linux, and Cobalt Strike, with the ability to script when required.
- Proficiency in security frameworks such as OWASP, MITRE ATT&CK, NIST, CIS Benchmarks, OSSTMM, PTES, and CREST.
- Proficiency in risk scoring and communication methodologies, including CVSS 3.1, CVSS 4.0, and 5×5 risk matrix.
- Minimally possess CREST CRT or OSCP, or be in the near pipeline of obtaining them.
- Strong analytical and problem-solving ability.
- Excellent written and verbal communication skills.
- Capable of preparing clear, structured, and professional client reports.
- Self-motivated, detail-oriented, and able to work independently or in a team.
Progress into senior or lead consultant roles, taking ownership of project delivery, mentorship of junior team members, leadership of complex client engagements, and managing client relationships.
Firmus provides consultants with opportunities to explore and develop cross-domain skills, including:
- Governance, Risk, and Compliance (GRC) assessments.
- Operational Technology (OT) cybersecurity engagements.
- Blue Team functions such as Managed Detection and Response (MDR), Incident Response, and Threat Hunting.
Key Skills
Ranked by relevanceReady to apply?
Join FIRMUS and take your career to the next level!
Application takes less than 5 minutes