Consultant, Penetration Testing & Vulnerability Assessment

About the job

PURPOSE:


  • Jobs at this level are responsible for carrying out a range of cybersecurity penetration testing and vulnerability assessment activities including assessment of threats and vulnerabilities, identification of deviations from required and/or acceptable configurations, and evaluation of existing level of risk.




Key Responsibilities:


Organizational Responsibilities


Follow all relevant cybersecurity penetration testing and vulnerability assessment policies, processes and standard operating procedures so that work is carried out in a controlled and consistent manner.

Operational Responsibilities

  • Conduct the necessary day-to-day activities with minimal supervision to ensure continuity of work
  • Follow-up on escalated cases /issues/questions of subordinates to ensure they are closed efficiently and in a timely manner
  • Execute non-intrusive penetration testing and vulnerability assessment in clients’ industrial control networks and systems
  • Identify and evaluate cybersecurity vulnerabilities in physical devices, and mobile devices analysis for indicators of compromise
  • Identify and evaluate cybersecurity vulnerabilities in applications, network devices, and infrastructure software
  • Perform vulnerability scanning on information systems to ensure protection has been put in place on those systems
  • Assess current technology infrastructure to identify key risks areas, and ensure adequate level of control are in place to address those risks
  • Execute social engineering campaigns to detect vulnerabilities related to the human factor
  • Perform simulation of phishing campaigns to determine employees’ awareness level against phishing attacks
  • Develop a collaborative, cloud-based penetration testing environment to allow dynamic creation of attack scenarios, and generation of reports
  • Coordinate cross-functionally to accomplish assigned tasks

People Management Responsibilities

Train junior staff on the different job activities to ensure transfer of know-how


Skills:


Network/Web/Mobile/Wireless pentesting

MITRE ATT&CK

OWASP




Competencies


Technical Writing

Automation/ Scripting and Integration

Vulnerabilities Assessment

Penetration Testing

Secure Programming

Technology Advising/Consulting



Qualifications:


Bachelor’s degree in Engineering or related technical discipline


Certifications:


OSCP

GMOB

GWAPT

GPEN

eWAPTX


Experience:

A minimum of 4 years of relevant experience with at least 2 years in a similar role


لنك التقديم 

https://www.linkedin.com/jobs/view/2980753977/?refId=LYdiHCLbaKv%2FyFkT8wlxbw%3D%3D&trackingId=fWuUBbm7KiFqJN1kg37Omg%3D%3D

تعليقات

المشاركات الشائعة من هذه المدونة

Possession Officer at Riyadh Metro Project.- Saudi National

Documentation Officer