Cybersecurity Vulnerability Analyst
Job Summary
- Receiving information and reports about hardware and software vulnerabilities; analysing the nature mechanics and effects of the vulnerabilities; and developing response strategies for detecting and repairing the vulnerabilities.
- Proactively managing vulnerabilities by performing vulnerability assessments penetration tests and reviewing the technical security compliance (deviation from a baseline configuration) of systems and services.
- Managing response to disclosed vulnerabilities for which no countermeasure is yet available.
- This service can involve communicating with vendors other CSIRTs technical experts consultant members and the individuals or groups who initially discovered or reported the vulnerability.
- Evaluates results of security audits and tests security findings priorities plans and implements remediation controls.
- Provides forensic analysis in response to information security incidents.
- Assesses security controls of new applications to establish compliance level and appropriate configuration.
- Performing vulnerability watch.
- Processing of incoming vulnerability warnings alerts and reports.
- Oversee the management of known vulnerabilities through established processes and procedures.
- Triage based on verification level of exposure and impact assessment.
- Analysing and examining vulnerabilities in hardware or software.
- Validating the existence of suspected vulnerabilities by determining where they are located and how they can be exploited.
- Reviewing source code using a debugger to determine where the vulnerability occurs or trying to reproduce the problem on a test system.
- Notifying the various parts of the Agency about the vulnerability and shares information about how to fix or mitigate the vulnerability.
- Verifying that the vulnerability response strategy has been successfully implemented.
- Performing regular vulnerability scans of system and applications writing reports including recommendations for improvements and following-up the remediation process for identified vulnerabilities.
- Providing regular reports and dashboards (based on KPIs) to monitor security improvements.
- Performing penetration tests and writing reports including recommendations for improvements.
- Reviewing the technical security compliance of systems against defined security baselines (gold configuration) writing reports and following-up the remediation process for identified non-compliance.
- Participating in the definition of security baselines.
- Provide activity reports to management to demonstrate service SLA and service quality.
Qualifications :
- Bachelors degree plus 8 years of IT relevant professional experience
- Minimum 5 years of experience at similar position
- Active EU Security Clearance is required
- Minimum English language skills (CEFR) : B2
- Knowledge of systems development life cycle
- Knowledge of operating systems security
- Knowledge of computer networks security
- Knowledge of security controls
- Knowledge of offensive and defensive security practices
- Knowledge of secure coding practices
- Possesses hands-on experience in ICT in the role of Cybersecurity Vulnerability Analyst
- Knowledge of system security vulnerabilities threats and exploit mechanisms penetration testing remediation techniques and risk analysis methodologies
- Knowledge of OWASP family standards
- Practical knowledge of designing and performing security tests
- Practical knowledge of Tenable vulnerability management suite NMAP Wireshark BurpSuite
- Analytical mind attention to details and an ability to pick things up quickly; problem solving skills
- Document report present and communicate with various stakeholders
- Develop codes scripts and programmes
- Identify and exploit vulnerabilities
- Conduct ethical hacking
- Think creatively and outside the box
- Identify and solve cybersecurity-related issues
- Communicate present and report to relevant stakeholders
- Use penetration testing tools effectively
- Conduct technical analysis and reporting
- Decompose and analyse systems to identify weaknesses and ineffective controls
- Review codes assess their security integrate cybersecurity solutions to the organisations infrastructure
- Configure solutions according to the organisations security policy
- Assess the security and performance of solutions
- Develop and test secure code and/or scripts
- Identify and troubleshoot cybersecurity-related issues
Specific requirements:
- Experience in vulnerabilities analysis
- Knowledge of risk assessment in the context of given vulnerability and its environment
- Experience in coordination and execution of PenTests
- Experience in implementing protections against the most common types of exploits for web apps
- Proficient in writing reports covering vulnerabilities and patch management
- Experience in reviewing current security controls and proposing improvements
- Experience in writing security procedures/policies with emphasis in information protection and data privacy
- Experience in administering security solutions Vulnerability platform WAF EDR
- Innovative approach to new technologies
Required certificates (At least 3 certifications among):
- GCED (GIAC Certified Enterprise Defender)
- GPPA (GIAC Certified Perimeter Protection Analyst)
- GCWN (GIAC Certified Windows Security Administrator)
- GCUX (GIAC Certified UNIX Security Administrator)
- GCCC (GIAC Certified Critical Controls)
- SSCP (ISC² Certified Systems Security Practitioner)
- GCWN (GIAC Certified Windows Security Administrator)
- GCUX (GIAC Certified UNIX Security Administrator)
- GCCC (GIAC Certified Critical Controls)
- GPEN (GIAC Certified Penetration Tester)
- GXPN (GIAC Certified Exploit Researcher and Advanced Penetration Tester)
- GMOB (GIAC Certified Mobile Device Security Analyst)
- NDS (EC-Council Certified Security and Vulnerability Assessor)
- ECSA (EC-Council Certified Security Analyst)
- GSNA (GIAC Certified Systems and Network Auditor)
- GSEC (GIAC Certified Security Essentials)
- ECSA (EC-Council Certified Security Analyst)
- SCPO (SABSA Certified Security Operations & Service Management Practitioner)
- ECSA (EC-Council Certified Security Analyst)
- or for any listed above an equivalent alternative certification recognized internationally (subject to acceptance as a valid credential by the Contracting Authority).
Remote Work :
No
Employment Type :
Full-time
About Company
Ar?s is a fully independent group of companies specialized in managing complex IT projects and systems for large organisations, focusing on state-of-the-art software development, business intelligence and infrastructure services. We are composed of 17 entities across 9 countries that ... View more