Cybersecurity Vulnerability Analyst
Job Description
ABOUT THE JOB
We are a large company with a start-up spirit. We organize ourselves into expert knowledge Units that collaborate with each other.
That's why we are looking for curious individuals who are motivated by challenges and eager to grow personally and professionally, to join our team and make a positive impact on the world through technology.
ARE YOU UP FOR THE CHALLENGE?
We want you to be a part of our team, from Warsaw, as a Cybersecurity Vulnerability Analyst.
WHAT WILL YOU DO IN YOUR DAY-TO-DAY?
- Monitor, analyse, validate and prioritise hardware and software vulnerabilities.
- Perform vulnerability assessments, scans, penetration tests and security compliance reviews.
- Develop, coordinate and verify remediation or mitigation strategies, including zero-day responses.
- Review source code, reproduce vulnerabilities and assess exploitability, exposure and impact.
- Evaluate audit and test findings, implement corrective controls and follow up remediation.
- Assess security controls and configurations for new systems and applications.
- Communicate vulnerability information and remediation guidance to internal teams, vendors, CSIRTs and technical experts.
- Conduct forensic analysis following information security incidents.
- Maintain vulnerability watch and process alerts, warnings and reports.
- Produce technical reports, dashboards and KPI-based management updates.
- Support the definition and enforcement of security baselines and gold configurations.
- Report on service quality, SLA performance and vulnerability-management activities.
WHAT DO WE EXPECT FROM YOU?
- Knowledge of systems, networks, security controls, secure coding and the systems development life cycle
- Hands-on experience in vulnerability analysis, penetration testing, ethical hacking and risk assessment.
- Practical knowledge of OWASP and common web-application exploits and protections.
- Proficient with Tenable, Nmap, Wireshark, Burp Suite, WAF and EDR solutions.
- Able to identify, exploit, assess and remediate vulnerabilities.
- Experience reviewing security controls, code and infrastructure, and recommending improvements.
- Skilled in developing secure scripts, configuring security solutions and troubleshooting cybersecurity issues.
- Strong technical reporting, policy writing and stakeholder communication skills.
- Analytical, detail-oriented, creative and quick to learn new technologies.
Certifications:
At least 3 certifications among:
[1] GCED (GIAC Certified Entreprise Defender)
[2] GPPA (GIAC Certified Perimeter Protection Analyst)
[3] GCWN (GIAC Certified Windows Security Administrator)
[4] GCUX (GIAC Certified UNIX Security Administrator)
[5] GCCC (GIAC Certified Critical Controls)
[6] SSCP ((ISC)2 Certified Systems Security Practitioner)
[7] GCWN (GIAC Certified Windows Security Administrator)
[8] GCUX (GIAC Certified UNIX Security Administrator)
[9] GCCC (GIAC Certified Critical Controls)
[10] GPEN (GIAC Certified Penetration Tester)
[11] GXPN (GIAC Certified Exploit Researcher and Advanced Penetration Tester)
[12] GMOB (GIAC Certified Mobile Device Security Analyst)
[13] NDS (EC-Council Certified Security and Vulnerability Assessor)
[14] ECSA (EC-Council Certified Security Analyst)
[15] GSNA (GIAC Certified Systems and Network Auditor)
[16] GSEC (GIAC Certified Security Essentials)
[17] ECSA (EC-Council Certified Security Analyst)
[18] SCPO (SABSA Certified Security Operations & Service Management Practitioner)
[19] ECSA (EC-Council Certified Security Analyst)
or for any listed above, an equivalent alternative certification recognized internationally (subject to acceptance as a valid credential by the Contracting Authority?
Will you join us in humanizing technology?