VAPT Engineer Salary in India
VAPT Engineer Salary in India
VAPT engineer salaries in India typically start around 4 to 7 LPA for entry-level roles, rise to 8 to 16 LPA at two to five years, and reach 18 to 35 LPA or higher for senior and lead positions. The range at every level is wide because compensation in this field is driven far more by demonstrable ability and employer type than by years of experience.
That last point is the one worth understanding, and it is why two people with identical experience can be 8 LPA apart. This guide covers what actually moves the number. If you are still deciding whether to enter the field, read what is VAPT first, and the VAPT engineer career path for the role itself.
Salary by experience level
| Level | Experience | Typical range (LPA) | Common titles |
|---|---|---|---|
| Entry | 0 to 1 years | 4 to 7 | Security Analyst, VAPT Trainee, Associate Consultant |
| Junior | 1 to 3 years | 7 to 12 | VAPT Engineer, Security Consultant |
| Mid | 3 to 5 years | 12 to 20 | Senior Consultant, Senior Penetration Tester |
| Senior | 5 to 8 years | 18 to 32 | Lead Pentester, Offensive Security Engineer |
| Lead / Principal | 8+ years | 30 to 60+ | Red Team Lead, Practice Head, Principal Consultant |
Treat these as bands, not promises. The overlap between bands is deliberate and real: a strong two-year engineer at a product company frequently out-earns a five-year engineer at a large services firm.
What actually moves the number
Experience is the weakest of the four factors below, which is not what most salary articles tell you.
1. Employer type (the biggest single factor)
| Employer type | Relative pay | What you trade |
|---|---|---|
| Large IT services (TCS, Infosys, Wipro, Accenture) | Lowest | Stability and brand for pay and depth of work |
| Big 4 consulting (Deloitte, EY, PwC, KPMG) | Moderate | Client variety and brand for long hours |
| Boutique security consultancies | Moderate to high | Deep technical work, less brand recognition |
| Product companies and startups | High | Depth in one product, sometimes equity |
| Global companies hiring remotely from India | Highest | Time zone overlap and a harder hiring bar |
| Independent consulting and bug bounty | Highly variable | All the risk, all the upside |
The gap between the top and bottom row for the same skill level is frequently 3x. Moving from a large services firm to a product company is the single most reliable way to increase security compensation in India, more than any certification.
2. Demonstrable ability
This field is unusually meritocratic on compensation because ability is unusually easy to verify. A candidate with public CVEs, Hall of Fame entries, or a portfolio of well-written disclosures negotiates from a different position than one with a certificate and no evidence.
We have seen candidates with under two years of experience clear offers above the "senior" band in the table above, purely on a public track record. See projects that get you interviews.
3. Specialisation
Generalist web application testing is the most commoditised part of the market, because it is what everyone trains for. Premium sits in the areas with a supply shortage:
- Cloud security across AWS, Azure and GCP
- AI and LLM security, currently the thinnest talent pool in the market
- Red teaming and adversary simulation
- Hardware, embedded and automotive security
- Source code review and secure SDLC
4. Certifications
Certifications matter less for salary than most candidates assume, and more for getting the interview. OSCP is the one that consistently shifts the conversation in technical hiring. CEH more often functions as an HR filter than a pay lever. Full comparison in OSCP vs CEH and ROI ranking in certifications ranked by ROI.
Salary by city
| City | Relative to national median | Note |
|---|---|---|
| Bangalore | Highest | Deepest product company concentration |
| Hyderabad | High | Growing fast, strong global capability centres |
| Delhi NCR (Gurgaon, Noida) | High | Consulting and BFSI heavy |
| Pune | Moderate to high | Good balance of pay against cost of living |
| Mumbai | Moderate to high | BFSI driven, compliance heavy work |
| Chennai | Moderate | Services heavy |
| Tier 2 cities | Lower | Remote roles have compressed this gap significantly |
Remote hiring has changed this table more than anything else in the last few years. A tester in Jaipur or Indore working remotely for a Bangalore product company earns Bangalore compensation at tier-two cost of living, which is the best arbitrage available in this field.
Why VAPT pay in India is unusually stable
A structural point that gets missed: a large share of Indian VAPT demand is compliance-driven rather than budget-driven.
CERT-In directions, RBI cyber security frameworks, SEBI CSCRF, ISO 27001 and PCI-DSS all mandate periodic security testing for regulated entities. That demand does not disappear in a downturn because it is a legal requirement, not a discretionary spend. Detail in CERT-In VAPT requirements.
The practical effect is that VAPT hiring in India has been steadier through hiring slowdowns than most engineering roles. It also means a meaningful share of the work is repetitive compliance testing rather than interesting research, which is a genuine trade-off worth knowing before you enter the field.
How to move up a band
- Build public evidence. Disclosures, writeups, tools, CVEs. This outperforms every other action on this list for negotiating leverage.
- Learn to write reports properly. The single most undertaught skill in the field. Testers who can communicate findings to executives move into lead roles years earlier. See how to write a VAPT report.
- Specialise into a shortage area. Cloud or AI security. Both currently pay a premium over generalist web testing.
- Change employer type. Services to product is usually a larger jump than any internal promotion.
- Get OSCP when you are genuinely ready. It changes the technical interview, not the HR screen.
- Learn the defensive side. Testers who understand detection and can talk to a SOC are far rarer than they should be, and they get lead roles. See red team vs blue team.
Related role salaries
- SOC analyst salary in India, typically lower at entry with a faster path to specialisation
- Cloud security engineer salary in India, currently among the highest bands in security
- Bug bounty earnings in India, highly variable and rarely a reliable primary income early on
How to get the entry-level role
The 4 to 7 LPA band is the hardest one to enter, because almost every listing at that level asks for experience nobody starting out has. What actually works:
- A portfolio that substitutes for experience: writeups, disclosures, a documented lab
- Applying to boutique consultancies, which hire on demonstrated skill far more readily than large firms
- An internship, even unpaid or short, at a security consultancy
- A resume written for the ATS, because most rejections happen before a human reads it. See cyber security resume guide.
Practise this
Nothing on this page helps until you can actually do the work. Hacklido is our free CTF and lab platform, open to everyone with no payment.
For structured preparation with a live mentor, the TCVE VAPT program covers web, network, API and AI security testing across three months, including the reporting skill that most programs skip.
Frequently asked questions
What is the starting salary for a VAPT engineer in India?
Entry-level roles typically fall between 4 and 7 LPA, with boutique security consultancies and product companies at the upper end and large IT services firms at the lower end.
Is VAPT a good career in India?
Yes, and unusually stable, because much of the demand is regulatory rather than discretionary. The trade-off is that a meaningful share of the work is repetitive compliance testing.
Does OSCP increase salary in India?
Indirectly. It rarely triggers an automatic raise, but it substantially changes which interviews you get and how technical interviewers assess you, which is where the compensation difference is decided.
Can a fresher get a VAPT job without experience?
Yes, but the portfolio has to do the work the experience would have. Public writeups, disclosed vulnerabilities and a documented home lab are what get freshers past the experience requirement.
Which pays more, VAPT or SOC analyst?
VAPT roles generally pay more at entry and mid level. SOC roles catch up at senior levels, particularly in detection engineering and threat hunting specialisations.
Do I need a computer science degree?
No. It helps with HR screening at large firms, but boutique consultancies and product companies in this field hire on demonstrated ability. Several of our placed students came from non-CS backgrounds.