Consultant, Penetration Testing & Vulnerability Assessment
About the job
PURPOSE:
- Jobs at this level are responsible for carrying out a range of cybersecurity penetration testing and vulnerability assessment activities including assessment of threats and vulnerabilities, identification of deviations from required and/or acceptable configurations, and evaluation of existing level of risk.
Key Responsibilities:
Organizational Responsibilities
Follow all relevant cybersecurity penetration testing and vulnerability assessment policies, processes and standard operating procedures so that work is carried out in a controlled and consistent manner.
Operational Responsibilities
- Conduct the necessary day-to-day activities with minimal supervision to ensure continuity of work
- Follow-up on escalated cases /issues/questions of subordinates to ensure they are closed efficiently and in a timely manner
- Execute non-intrusive penetration testing and vulnerability assessment in clients’ industrial control networks and systems
- Identify and evaluate cybersecurity vulnerabilities in physical devices, and mobile devices analysis for indicators of compromise
- Identify and evaluate cybersecurity vulnerabilities in applications, network devices, and infrastructure software
- Perform vulnerability scanning on information systems to ensure protection has been put in place on those systems
- Assess current technology infrastructure to identify key risks areas, and ensure adequate level of control are in place to address those risks
- Execute social engineering campaigns to detect vulnerabilities related to the human factor
- Perform simulation of phishing campaigns to determine employees’ awareness level against phishing attacks
- Develop a collaborative, cloud-based penetration testing environment to allow dynamic creation of attack scenarios, and generation of reports
- Coordinate cross-functionally to accomplish assigned tasks
People Management Responsibilities
Train junior staff on the different job activities to ensure transfer of know-how
Skills:
Network/Web/Mobile/Wireless pentesting
MITRE ATT&CK
OWASP
Competencies
Technical Writing
Automation/ Scripting and Integration
Vulnerabilities Assessment
Penetration Testing
Secure Programming
Technology Advising/Consulting
Qualifications:
Bachelor’s degree in Engineering or related technical discipline
Certifications:
OSCP
GMOB
GWAPT
GPEN
eWAPTX
Experience:
A minimum of 4 years of relevant experience with at least 2 years in a similar role
لنك التقديم
تعليقات
إرسال تعليق