Title: Vulnerability Assessment & Penetration Testing (VAPT) Analyst - ITSD
Company Name: Mutual Trust Bank PLC
Vacancy: --
Age: Na
Job Location: Dhaka
Salary: --
Experience:
2–3 years of experience in vulnerability assessments, penetration testing, ethical hacking, or offensive security roles.
Preferred certifications: eJPT, CEH, or similar industry-recognized certifications in offensive security.
Familiarity with OWASP Top 10, MITRE ATT&CK, CVSS scoring, and secure coding principles.
Practical experience with penetration testing tools and scripting (Python, Bash, PowerShell).
Knowledge of networks, web protocols, operating systems (Windows/Linux), and authentication mechanisms.
Clear, concise reporting skills for both technical and non-technical audiences.
Experience in defensive security or exposure to bug bounty programs, CTF competitions, or security communities is a plus.
Strong analytical, communication, and collaboration skills.
The incumbent will be responsible for conducting vulnerability assessments and penetration testing across the Bank’s applications and infrastructure. This role is focused on identifying, analyzing, and reporting security weaknesses while supporting development and infrastructure teams in timely remediation.
Key Responsibilities:
Conduct end-to-end vulnerability assessments and penetration testing of web/mobile applications, APIs, and internal/external infrastructure.
Utilize tools such as Burp Suite, Nmap, Nessus, Metasploit, SQLmap, and OWASP ZAP in combination with manual testing techniques.
Analyze findings for impact and exploitability; document and present technical and executive-level reports with clear remediation guidance.
Define engagement scopes, rules of engagement, and test plans.
Collaborate with development and infrastructure teams to validate and track resolution of vulnerabilities.
Maintain detailed documentation of test results, methodologies, and security assessment procedures.
Continuously monitor the security landscape and contribute to process improvements and knowledge sharing within the team.
Support and complement the organization’s broader security posture through VAPT, secure coding, and offensive security inputs.
| University | Percentage (%) |
|---|---|
| National University | 7.02% |
| Daffodil International University (DIU) | 5.57% |
| Jahangirnagar University | 4.36% |
| Jagannath University | 3.15% |
| North South University | 2.91% |
| University of Dhaka | 2.66% |
| American International University Bangladesh (AIUB) | 2.18% |
| 2.18% | |
| Bangladesh University of Professionals | 2.18% |
| East West University | 1.94% |
| Age Range | Percentage (%) |
|---|---|
| 20-30 | 69.49% |
| 31-35 | 18.64% |
| 36-40 | 6.30% |
| 40+ | 3.63% |
| Salary Range | Percentage (%) |
|---|---|
| 0-20K | 6.05% |
| 20K-30K | 30.75% |
| 30K-40K | 18.16% |
| 40K-50K | 13.08% |
| 50K+ | 31.96% |
| Experience Range | Percentage (%) |
|---|---|
| 0 years (Freshers) | 21.31% |
| 0.1 - 1 years | 11.38% |
| 1.1 - 3 years | 22.52% |
| 3.1 - 5 years | 18.64% |
| 5+ years | 26.15% |