VAPT and Security Compliance Support(CERT-IN Empanelled Vendor Required) -- 3
Budget: ₹750 – ₹1,250 INR
Project Overview
We are seeking the services of a only CERT-IN empanelled cybersecurity vendor or professional to carry out a Vulnerability Assessment and Penetration Testing (VAPT) and assist in completing mandatory client security compliance questionnaires. This engagement is crucial for vendor onboarding with major corporate clients and insurance partners.
Scope of Work:
1. Vulnerability Assessment & Penetration Testing (VAPT):
o Perform comprehensive internal and external VAPT of our infrastructure, including web applications, APIs, servers, and endpoints.
o Assess network and application layer vulnerabilities.
o Provide a detailed report including:
Risk categorization (High/Medium/Low)
Technical findings with evidence (screenshots, logs)
Suggested remediation
Final re-validation report after fixes
2. Compliance Documentation Support:
o Assist in completing two client security assessments:
“Partner Onboarding – Security Parameters of Client Environment”
“Digit – Vendor Self Assessment Questionnaire”
o Align responses with industry best practices and regulatory standards (ISO 27001, NIST, CERT-IN).
o Provide documented evidence such as:
Information Security Policy
Secure configuration baselines
Data classification and protection policies
Business continuity and disaster recovery plans
Access control and monitoring procedures
3. Evaluation & Risk Score Optimization:
o Understand the evaluation matrix and risk scoring methodology used by clients.
o Recommend corrective actions to improve security posture and compliance scores.
o Ensure documentation is audit-ready and presentable.
Mandatory Requirement:
• The selected professional must be a CERT-IN empanelled vendor or work in association with one. Proof of empanelment will be required.
Deliverables:
• Initial and Final VAPT Reports
• Completed security assessment questionnaires
• Supporting documentation (security policies, technical artifacts)
• Advisory notes on risk mitigation and compliance readiness
Required Skills:
• Vulnerability Assessment & Penetration Testing (VAPT)
• Experience with CERT-IN standards and compliance
• Security Questionnaire Handling & Audit Documentation
• Knowledge of ISO 27001, NIST, and Indian IT Act compliance
• Network Security & Web Application Security Testing
• Firewall, IDS/IPS, and Endpoint Security Assessment
• Report Writing – Technical and Non-Technical (Audit-ready)
• Risk Analysis & Mitigation Planning
• Incident Response and Business Continuity Knowledge
• Familiarity with tools like Burp Suite, Nmap, Nessus, OWASP ZAP, Metasploit
• Certifications (preferred): CEH, OSCP, CISSP, CISA
Timeline:
• Kickoff: Immediate
• Duration: 2-3 weeks (negotiable based on availability and scope)
Budget:
• Please quote your fixed price for the complete engagement or hourly rate.
• Attach sample VAPT reports or redacted past project documentation, if available.
URl.:-
1. https://motor-insurance.netlify.app/MOTOR
2.https://utility-update-repo.vercel.app/
We are seeking the services of a only CERT-IN empanelled cybersecurity vendor or professional to carry out a Vulnerability Assessment and Penetration Testing (VAPT) and assist in completing mandatory client security compliance questionnaires. This engagement is crucial for vendor onboarding with major corporate clients and insurance partners.
Scope of Work:
1. Vulnerability Assessment & Penetration Testing (VAPT):
o Perform comprehensive internal and external VAPT of our infrastructure, including web applications, APIs, servers, and endpoints.
o Assess network and application layer vulnerabilities.
o Provide a detailed report including:
Risk categorization (High/Medium/Low)
Technical findings with evidence (screenshots, logs)
Suggested remediation
Final re-validation report after fixes
2. Compliance Documentation Support:
o Assist in completing two client security assessments:
“Partner Onboarding – Security Parameters of Client Environment”
“Digit – Vendor Self Assessment Questionnaire”
o Align responses with industry best practices and regulatory standards (ISO 27001, NIST, CERT-IN).
o Provide documented evidence such as:
Information Security Policy
Secure configuration baselines
Data classification and protection policies
Business continuity and disaster recovery plans
Access control and monitoring procedures
3. Evaluation & Risk Score Optimization:
o Understand the evaluation matrix and risk scoring methodology used by clients.
o Recommend corrective actions to improve security posture and compliance scores.
o Ensure documentation is audit-ready and presentable.
Mandatory Requirement:
• The selected professional must be a CERT-IN empanelled vendor or work in association with one. Proof of empanelment will be required.
Deliverables:
• Initial and Final VAPT Reports
• Completed security assessment questionnaires
• Supporting documentation (security policies, technical artifacts)
• Advisory notes on risk mitigation and compliance readiness
Required Skills:
• Vulnerability Assessment & Penetration Testing (VAPT)
• Experience with CERT-IN standards and compliance
• Security Questionnaire Handling & Audit Documentation
• Knowledge of ISO 27001, NIST, and Indian IT Act compliance
• Network Security & Web Application Security Testing
• Firewall, IDS/IPS, and Endpoint Security Assessment
• Report Writing – Technical and Non-Technical (Audit-ready)
• Risk Analysis & Mitigation Planning
• Incident Response and Business Continuity Knowledge
• Familiarity with tools like Burp Suite, Nmap, Nessus, OWASP ZAP, Metasploit
• Certifications (preferred): CEH, OSCP, CISSP, CISA
Timeline:
• Kickoff: Immediate
• Duration: 2-3 weeks (negotiable based on availability and scope)
Budget:
• Please quote your fixed price for the complete engagement or hourly rate.
• Attach sample VAPT reports or redacted past project documentation, if available.
URl.:-
1. https://motor-insurance.netlify.app/MOTOR
2.https://utility-update-repo.vercel.app/
Related categories:
Web Security
Testing / QA
Computer Security
Website Testing
Certified Ethical Hacking