Skip to content
← Back to job listings

Cybersecurity Vulnerability Analyst

ARHS · Warsaw, Masovian Voivodeship, Poland

CybersecuritySenior LevelExternal listingfull-time3 days ago

About The Role

  • Receiving information and reports about hardware and software vulnerabilities; analysing the nature, mechanics, and effects of the vulnerabilities; and developing response strategies for detecting and repairing the vulnerabilities.
  • Proactively managing vulnerabilities by performing vulnerability assessments, penetration tests and reviewing the technical security compliance (deviation from a baseline configuration) of systems and services.
  • Managing response to disclosed vulnerabilities for which no countermeasure is yet available.
  • This service can involve communicating with vendors, other CSIRTs, technical experts, consultant members, and the individuals or groups who initially discovered or reported the vulnerability.
  • Evaluates results of security audits and tests, security findings, priorities, plans, and implements remediation controls.
  • Provides forensic analysis in response to information security incidents.
  • Assesses security controls of new applications to establish compliance level and appropriate configuration.
  • Performing vulnerability watch.
  • Processing of incoming vulnerability warnings, alerts and reports.
  • Oversee the management of known vulnerabilities through established processes and procedures.
  • Triage based on verification, level of exposure and impact assessment.
  • Analysing and examining vulnerabilities in hardware or software.
  • Validating the existence of suspected vulnerabilities by determining where they are located and how they can be exploited.
  • Reviewing source code, using a debugger to determine where the vulnerability occurs, or trying to reproduce the problem on a test system.
  • Notifying the various parts of the Agency about the vulnerability and shares information about how to fix or mitigate the vulnerability.
  • Verifying that the vulnerability response strategy has been successfully implemented.
  • Performing regular vulnerability scans of system and applications, writing reports including recommendations for improvements and following-up the remediation process for identified vulnerabilities.
  • Providing regular reports and dashboards (based on KPIs) to monitor security improvements.
  • Performing penetration tests and writing reports including recommendations for improvements.
  • Reviewing the technical security compliance of systems against defined security baselines (gold configuration), writing reports and following-up the remediation process for identified non-compliance.
  • Participating in the definition of security baselines.
  • Provide activity reports to management to demonstrate service SLA and service quality.
  • Bachelor's degree plus 8 years of IT relevant professional experience 
  • Minimum 5 years of experience at similar position 
  • Active EU Security Clearance is required
  • Minimum English language skills (CEFR) : B2
  • Knowledge of systems development life cycle
  • Knowledge of operating systems security
  • Knowledge of computer networks security
  • Knowledge of security controls
  • Knowledge of offensive and defensive security practices
  • Knowledge of secure coding practices
  • Possesses hands-on experience in ICT in the role of Cybersecurity Vulnerability Analyst
  • Knowledge of system security vulnerabilities, threats and exploit mechanisms, penetration testing, remediation techniques and risk analysis methodologies
  • Knowledge of OWASP family standards
  • Practical knowledge of designing and performing security tests
  • Practical knowledge of Tenable vulnerability management suite, NMAP, Wireshark, BurpSuite
  • Analytical mind, attention to details and an ability to pick things up quickly; problem solving skills
  • Document, report, present and communicate with various stakeholders
  • Develop codes, scripts and programmes
  • Identify and exploit vulnerabilities
  • Conduct ethical hacking
  • Think creatively and outside the box
  • Identify and solve cybersecurity-related issues
  • Communicate, present and report to relevant stakeholders
  • Use penetration testing tools effectively
  • Conduct technical analysis and reporting
  • Decompose and analyse systems to identify weaknesses and ineffective controls
  • Review codes, assess their security, integrate cybersecurity solutions to the organisation's infrastructure
  • Configure solutions according to the organisation's security policy
  • Assess the security and performance of solutions
  • Develop and test secure code and/or scripts
  • Identify and troubleshoot cybersecurity-related issues

Specific requirements

  • Experience in vulnerabilities analysis
  • Knowledge of risk assessment in the context of given vulnerability and its environment
  • Experience in coordination and execution of PenTests
  • Experience in implementing protections against the most common types of exploits for web apps
  • Proficient in writing reports covering vulnerabilities and patch management
  • Experience in reviewing current security controls and proposing improvements
  • Experience in writing security procedures/policies with emphasis in information protection and data privacy
  • Experience in administering security solutions – Vulnerability platform, WAF, EDR
  • Innovative approach to new technologies

Required certificates  (At least 3 certifications among)

  • GCED (GIAC Certified Enterprise Defender)
  • GPPA (GIAC Certified Perimeter Protection Analyst)
  • GCWN (GIAC Certified Windows Security Administrator)
  • GCUX (GIAC Certified UNIX Security Administrator)
  • GCCC (GIAC Certified Critical Controls)
  • SSCP (ISC² Certified Systems Security Practitioner)
  • GCWN (GIAC Certified Windows Security Administrator)
  • GCUX (GIAC Certified UNIX Security Administrator)
  • GCCC (GIAC Certified Critical Controls)
  • GPEN (GIAC Certified Penetration Tester)
  • GXPN (GIAC Certified Exploit Researcher and Advanced Penetration Tester)
  • GMOB (GIAC Certified Mobile Device Security Analyst)
  • NDS (EC-Council Certified Security and Vulnerability Assessor)
  • ECSA (EC-Council Certified Security Analyst)
  • GSNA (GIAC Certified Systems and Network Auditor)
  • GSEC (GIAC Certified Security Essentials)
  • ECSA (EC-Council Certified Security Analyst)
  • SCPO (SABSA Certified Security Operations & Service Management Practitioner)
  • ECSA (EC-Council Certified Security Analyst)
  • or for any listed above, an equivalent alternative certification recognized internationally (subject to acceptance as a valid credential by the Contracting Authority).

This is an external listing. JobSpring does not represent or verify the employer. Report this listing