Cybersecurity Vulnerability Analyst

ARHS


Job Location:

Warsaw - Poland

Monthly Salary: Not Disclosed
Posted on: 4 hours ago
Vacancies: 1 Vacancy

Job Summary

  • Receiving information and reports about hardware and software vulnerabilities; analysing the nature mechanics and effects of the vulnerabilities; and developing response strategies for detecting and repairing the vulnerabilities.
  • Proactively managing vulnerabilities by performing vulnerability assessments penetration tests and reviewing the technical security compliance (deviation from a baseline configuration) of systems and services.
  • Managing response to disclosed vulnerabilities for which no countermeasure is yet available.
  • This service can involve communicating with vendors other CSIRTs technical experts consultant members and the individuals or groups who initially discovered or reported the vulnerability.
  • Evaluates results of security audits and tests security findings priorities plans and implements remediation controls.
  • Provides forensic analysis in response to information security incidents.
  • Assesses security controls of new applications to establish compliance level and appropriate configuration.
  • Performing vulnerability watch.
  • Processing of incoming vulnerability warnings alerts and reports.
  • Oversee the management of known vulnerabilities through established processes and procedures.
  • Triage based on verification level of exposure and impact assessment.
  • Analysing and examining vulnerabilities in hardware or software.
  • Validating the existence of suspected vulnerabilities by determining where they are located and how they can be exploited.
  • Reviewing source code using a debugger to determine where the vulnerability occurs or trying to reproduce the problem on a test system.
  • Notifying the various parts of the Agency about the vulnerability and shares information about how to fix or mitigate the vulnerability.
  • Verifying that the vulnerability response strategy has been successfully implemented.
  • Performing regular vulnerability scans of system and applications writing reports including recommendations for improvements and following-up the remediation process for identified vulnerabilities.
  • Providing regular reports and dashboards (based on KPIs) to monitor security improvements.
  • Performing penetration tests and writing reports including recommendations for improvements.
  • Reviewing the technical security compliance of systems against defined security baselines (gold configuration) writing reports and following-up the remediation process for identified non-compliance.
  • Participating in the definition of security baselines.
  • Provide activity reports to management to demonstrate service SLA and service quality.

Qualifications :

  • Bachelors degree plus 8 years of IT relevant professional experience 
  • Minimum 5 years of experience at similar position 
  • Active EU Security Clearance is required
  • Minimum English language skills (CEFR) : B2
  • Knowledge of systems development life cycle
  • Knowledge of operating systems security
  • Knowledge of computer networks security
  • Knowledge of security controls
  • Knowledge of offensive and defensive security practices
  • Knowledge of secure coding practices
  • Possesses hands-on experience in ICT in the role of Cybersecurity Vulnerability Analyst
  • Knowledge of system security vulnerabilities threats and exploit mechanisms penetration testing remediation techniques and risk analysis methodologies
  • Knowledge of OWASP family standards
  • Practical knowledge of designing and performing security tests
  • Practical knowledge of Tenable vulnerability management suite NMAP Wireshark BurpSuite
  • Analytical mind attention to details and an ability to pick things up quickly; problem solving skills
  • Document report present and communicate with various stakeholders
  • Develop codes scripts and programmes
  • Identify and exploit vulnerabilities
  • Conduct ethical hacking
  • Think creatively and outside the box
  • Identify and solve cybersecurity-related issues
  • Communicate present and report to relevant stakeholders
  • Use penetration testing tools effectively
  • Conduct technical analysis and reporting
  • Decompose and analyse systems to identify weaknesses and ineffective controls
  • Review codes assess their security integrate cybersecurity solutions to the organisations infrastructure
  • Configure solutions according to the organisations security policy
  • Assess the security and performance of solutions
  • Develop and test secure code and/or scripts
  • Identify and troubleshoot cybersecurity-related issues

Specific requirements:

  • Experience in vulnerabilities analysis
  • Knowledge of risk assessment in the context of given vulnerability and its environment
  • Experience in coordination and execution of PenTests
  • Experience in implementing protections against the most common types of exploits for web apps
  • Proficient in writing reports covering vulnerabilities and patch management
  • Experience in reviewing current security controls and proposing improvements
  • Experience in writing security procedures/policies with emphasis in information protection and data privacy
  • Experience in administering security solutions Vulnerability platform WAF EDR
  • Innovative approach to new technologies

Required certificates (At least 3 certifications among):

  • GCED (GIAC Certified Enterprise Defender)
  • GPPA (GIAC Certified Perimeter Protection Analyst)
  • GCWN (GIAC Certified Windows Security Administrator)
  • GCUX (GIAC Certified UNIX Security Administrator)
  • GCCC (GIAC Certified Critical Controls)
  • SSCP (ISC² Certified Systems Security Practitioner)
  • GCWN (GIAC Certified Windows Security Administrator)
  • GCUX (GIAC Certified UNIX Security Administrator)
  • GCCC (GIAC Certified Critical Controls)
  • GPEN (GIAC Certified Penetration Tester)
  • GXPN (GIAC Certified Exploit Researcher and Advanced Penetration Tester)
  • GMOB (GIAC Certified Mobile Device Security Analyst)
  • NDS (EC-Council Certified Security and Vulnerability Assessor)
  • ECSA (EC-Council Certified Security Analyst)
  • GSNA (GIAC Certified Systems and Network Auditor)
  • GSEC (GIAC Certified Security Essentials)
  • ECSA (EC-Council Certified Security Analyst)
  • SCPO (SABSA Certified Security Operations & Service Management Practitioner)
  • ECSA (EC-Council Certified Security Analyst)
  • or for any listed above an equivalent alternative certification recognized internationally (subject to acceptance as a valid credential by the Contracting Authority).

Remote Work :

No


Employment Type :

Full-time

Receiving information and reports about hardware and software vulnerabilities; analysing the nature mechanics and effects of the vulnerabilities; and developing response strategies for detecting and repairing the vulnerabilities.Proactively managing vulnerabilities by performing vulnerability assess...

About Company

Company Logo

Ar?s is a fully independent group of companies specialized in managing complex IT projects and systems for large organisations, focusing on state-of-the-art software development, business intelligence and infrastructure services. We are composed of 17 entities across 9 countries that ... View more

View Profile View Profile