Vulnerability Assessment & Web Pentesting Intern
Perform hands-on web vulnerability scans, manual OWASP Top 10 testing, Burp Suite analysis, and remediation drafting under senior ethical hacker guidance.
Role Overview & Operational Scope
This is an intensive, practical training ground for ethical hackers. You will work on actual test applications, identify real security oversights, and learn how to present actionable findings to developers.
Key Responsibilities & Production Deliverables
- Execute guided vulnerability assessments on web applications following OWASP guidelines.
- Use Burp Suite, Nmap, and open-source scanners to analyze HTTP requests and response headers.
- Draft clear vulnerability reports detailing attack steps, risk severity, and exact remediation advice.
- Participate in security lab exercises and weekly technical debriefs with senior pentesting leads.
- Develop simple automation scripts in Python or Bash to streamline reconnaissance.
Mandatory Foundational Knowledge
- Good understanding of web basics: HTTP/HTTPS methods, headers, cookies, sessions, and status codes.
- Familiarity with common web vulnerabilities: SQLi, XSS, CSRF, IDOR, and sensitive data exposure.
- Basic familiarity with Linux command line and networking concepts (ports, DNS, IP addresses).
Mandatory Practical Skills & Architecture
- Ability to configure and use Burp Suite Community/Pro for intercepting browser traffic.
- Basic Python scripting for making automated requests or parsing output files.
- Clear written English for drafting bug descriptions and impact summaries.
Problem Solving, Execution Rigor & Curiosity
- High personal ethics, honesty, and strict adherence to non-disclosure and authorized testing boundaries.
- Eagerness to spend hours methodically testing edge cases and discovering hidden application behavior.
- Enthusiasm for CTFs (Capture The Flag) and hands-on security challenges.
5-Day Live Technical Evaluation Milestone
5-Day Live Practical Milestone: Complete a black-box security evaluation of our designated lab application, document all confirmed vulnerabilities with proof-of-concept payloads, and submit a remediation report (strictly 5 working days). High performers earn immediate PPO conversion.
Institutional Hiring Protocol: Candidates who pass initial resume screening are invited to a live, practical evaluation milestone spanning strictly not more than 5 working days. Verifiable completion and code audit by your assigned senior engineering mentor is the sole prerequisite for official corporate offer letter issuance.
Compensation, Total Rewards & Advancement
- Monthly paid fellowship (₹10,000–₹18,000/month) with project incentives.
- Direct PPO track into Full-Time Penetration Tester (₹7,00,000–₹12,00,000 CTC).
- Official Cehpoint Verified Internship Certificate and recommendation letter.
- Free access to proprietary cyber security courses and lab environments.
Dedicated Inquiries Inbox for This Role
Have questions regarding architecture scope or wish to share private research repos directly? Messages sent to this address route straight to the engineering leads reviewing this opening.
vulnerability-assessment-pentest-careers@cehpoint.co.in
Open Mail Client →