Security Analyst – VAPT & Penetration Testing

BAE Systems
Doha
Workplace: OnsiteFull timeFunction: CybersecuritySkills: ["Detail-oriented","Analytical thinking","Communication","Collaboration"]

Conduct internal and external penetration tests across networks, servers, firewalls, endpoints, and infrastructure, including web application and API security testing. Validate vulnerabilities and perform controlled exploitation to assess real impact, severity, and business risk. Review source code, support SAST/DAST activities, assess cloud and operating system security, and use tools such as Burp Suite, Nmap, Nessus, Metasploit, Wireshark, and Kali Linux. Deliver detailed reports and coordinate remediation and retesting.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
BAE Systems
BAE Systems
1 week ago

Security Analyst – VAPT & Penetration Testing

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 11 hours agoStatus: Live

Job Summary

Conduct internal and external penetration tests across networks, servers, firewalls, endpoints, and infrastructure, including web application and API security testing. Validate vulnerabilities and perform controlled exploitation to assess real impact, severity, and business risk. Review source code, support SAST/DAST activities, assess cloud and operating system security, and use tools such as Burp Suite, Nmap, Nessus, Metasploit, Wireshark, and Kali Linux. Deliver detailed reports and coordinate remediation and retesting.
Location: Doha
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Conduct internal and external penetration testing across networks, servers, firewalls, endpoints, and infrastructure.
  • •Perform web application and API penetration testing, including OWASP vulnerability testing.
  • •Manually validate vulnerabilities and false positives, and perform controlled exploitation to determine impact and severity.
  • •Assess security of network devices and infrastructure components, including VPNs, load balancers, routers, and switches.
  • •Prepare penetration-testing and vulnerability-assessment reports and support remediation through retesting and validation.

Key Requirements

  • •Strong hands-on experience with vulnerability assessment and penetration testing (VAPT) across networks, applications, APIs, and infrastructure.
  • •Experience conducting web application and API penetration testing, including testing against OWASP vulnerabilities.
  • •Ability to perform vulnerability exploitation, manual validation of findings/false positives, and assess actual impact and severity.
  • •Knowledge of cybersecurity standards and frameworks including OWASP, NIST, ISO/IEC 27001, and PCI DSS.
  • •Hands-on security tooling experience including Burp Suite, Nmap, Nessus, Metasploit, Wireshark, and Kali Linux.
Experience:Cybersecurity
Skills:Detail-orientedAnalytical thinkingCommunicationCollaboration
Tech Stack:Burp SuiteNmapNessusMetasploitWiresharkKali LinuxPythonOWASPNISTISO/IEC 27001PCI DSSSASTDAST

Company Brief

BAE Systems
Multinational defence, security and aerospace company designing, manufacturing and supporting military and civilian systems including naval ships, submarines, aircraft, cyber solutions and electronic systems for governments and commercial customers.
Industry: Defense Manufacturing
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: London, United Kingdom
Founded: 1999
WebsiteLinkedIn