← Back to job listings
AR
Cybersecurity Vulnerability Analyst
ARHS · Warsaw, Masovian Voivodeship, Poland
About The Role
- Receiving information and reports about hardware and software vulnerabilities; analysing the nature, mechanics, and effects of the vulnerabilities; and developing response strategies for detecting and repairing the vulnerabilities.
- Proactively managing vulnerabilities by performing vulnerability assessments, penetration tests and reviewing the technical security compliance (deviation from a baseline configuration) of systems and services.
- Managing response to disclosed vulnerabilities for which no countermeasure is yet available.
- This service can involve communicating with vendors, other CSIRTs, technical experts, consultant members, and the individuals or groups who initially discovered or reported the vulnerability.
- Evaluates results of security audits and tests, security findings, priorities, plans, and implements remediation controls.
- Provides forensic analysis in response to information security incidents.
- Assesses security controls of new applications to establish compliance level and appropriate configuration.
- Performing vulnerability watch.
- Processing of incoming vulnerability warnings, alerts and reports.
- Oversee the management of known vulnerabilities through established processes and procedures.
- Triage based on verification, level of exposure and impact assessment.
- Analysing and examining vulnerabilities in hardware or software.
- Validating the existence of suspected vulnerabilities by determining where they are located and how they can be exploited.
- Reviewing source code, using a debugger to determine where the vulnerability occurs, or trying to reproduce the problem on a test system.
- Notifying the various parts of the Agency about the vulnerability and shares information about how to fix or mitigate the vulnerability.
- Verifying that the vulnerability response strategy has been successfully implemented.
- Performing regular vulnerability scans of system and applications, writing reports including recommendations for improvements and following-up the remediation process for identified vulnerabilities.
- Providing regular reports and dashboards (based on KPIs) to monitor security improvements.
- Performing penetration tests and writing reports including recommendations for improvements.
- Reviewing the technical security compliance of systems against defined security baselines (gold configuration), writing reports and following-up the remediation process for identified non-compliance.
- Participating in the definition of security baselines.
- Provide activity reports to management to demonstrate service SLA and service quality.
- Bachelor's degree plus 8 years of IT relevant professional experience 
- Minimum 5 years of experience at similar position 
- Active EU Security Clearance is required
- Minimum English language skills (CEFR) : B2
- Knowledge of systems development life cycle
- Knowledge of operating systems security
- Knowledge of computer networks security
- Knowledge of security controls
- Knowledge of offensive and defensive security practices
- Knowledge of secure coding practices
- Possesses hands-on experience in ICT in the role of Cybersecurity Vulnerability Analyst
- Knowledge of system security vulnerabilities, threats and exploit mechanisms, penetration testing, remediation techniques and risk analysis methodologies
- Knowledge of OWASP family standards
- Practical knowledge of designing and performing security tests
- Practical knowledge of Tenable vulnerability management suite, NMAP, Wireshark, BurpSuite
- Analytical mind, attention to details and an ability to pick things up quickly; problem solving skills
- Document, report, present and communicate with various stakeholders
- Develop codes, scripts and programmes
- Identify and exploit vulnerabilities
- Conduct ethical hacking
- Think creatively and outside the box
- Identify and solve cybersecurity-related issues
- Communicate, present and report to relevant stakeholders
- Use penetration testing tools effectively
- Conduct technical analysis and reporting
- Decompose and analyse systems to identify weaknesses and ineffective controls
- Review codes, assess their security, integrate cybersecurity solutions to the organisation's infrastructure
- Configure solutions according to the organisation's security policy
- Assess the security and performance of solutions
- Develop and test secure code and/or scripts
- Identify and troubleshoot cybersecurity-related issues
Specific requirements
- Experience in vulnerabilities analysis
- Knowledge of risk assessment in the context of given vulnerability and its environment
- Experience in coordination and execution of PenTests
- Experience in implementing protections against the most common types of exploits for web apps
- Proficient in writing reports covering vulnerabilities and patch management
- Experience in reviewing current security controls and proposing improvements
- Experience in writing security procedures/policies with emphasis in information protection and data privacy
- Experience in administering security solutions – Vulnerability platform, WAF, EDR
- Innovative approach to new technologies
Required certificates  (At least 3 certifications among)
- GCED (GIAC Certified Enterprise Defender)
- GPPA (GIAC Certified Perimeter Protection Analyst)
- GCWN (GIAC Certified Windows Security Administrator)
- GCUX (GIAC Certified UNIX Security Administrator)
- GCCC (GIAC Certified Critical Controls)
- SSCP (ISC² Certified Systems Security Practitioner)
- GCWN (GIAC Certified Windows Security Administrator)
- GCUX (GIAC Certified UNIX Security Administrator)
- GCCC (GIAC Certified Critical Controls)
- GPEN (GIAC Certified Penetration Tester)
- GXPN (GIAC Certified Exploit Researcher and Advanced Penetration Tester)
- GMOB (GIAC Certified Mobile Device Security Analyst)
- NDS (EC-Council Certified Security and Vulnerability Assessor)
- ECSA (EC-Council Certified Security Analyst)
- GSNA (GIAC Certified Systems and Network Auditor)
- GSEC (GIAC Certified Security Essentials)
- ECSA (EC-Council Certified Security Analyst)
- SCPO (SABSA Certified Security Operations & Service Management Practitioner)
- ECSA (EC-Council Certified Security Analyst)
- or for any listed above, an equivalent alternative certification recognized internationally (subject to acceptance as a valid credential by the Contracting Authority).
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring