Principal Consultant, Penetration Testing & Vulnerability Assessment
About the job
PURPOSE:
- Jobs at this level are responsible for carrying out a range of cybersecurity penetration testing and vulnerability assessment activities including supervising assessment of threats and vulnerabilities, identification of deviations from required and/or acceptable configurations, and evaluation of existing level of risk to recommend appropriate remediation measures.
Key Responsibilities:
Organizational Responsibilities
Follow all relevant cybersecurity penetration testing and vulnerability assessment policies, processes and standard operating procedures so that work is carried out in a controlled and consistent manner.
Operational Responsibilities
- Supervise the day-to-day activities of subordinates to ensure that work processes are implemented as designed and in compliance with established standards and procedures
- Establish service level agreements with relevant stakeholders as per the SITE’s policies and procedures
- Conduct non-intrusive penetration testing and vulnerability assessment in clients’ industrial control networks and systems
- Supervise the identification and evaluation of cybersecurity vulnerabilities in physical devices, and mobile devices analysis for indicators of compromise
- Supervise the identification and evaluation of cybersecurity vulnerabilities in applications, network devices, and infrastructure software
- Oversee vulnerability scanning on information systems to ensure protection has been put in place on those systems
- Supervise the assessment of current technology infrastructure to identify key risks areas, and ensure adequate level of control are in place to address those risks
- Assist in designing social engineering campaigns to detect vulnerabilities related to the human factor
- Ensure proper coordination of phishing campaigns to determine employees’ awareness level against phishing attacks
- Supervise the development of a collaborative, cloud-based penetration testing environment to allow dynamic creation of attack scenarios, and generation of reports
- Supervise proper tasks allocation across team members and adherence to standards
- Coordinate cross-functionally to accomplish assigned tasks
- Support in developing related high-level reports for reporting and decision-making purposes
People Management Responsibilities
§ Develop and motivate subordinates to ensure transfer of know-how and maintain a positive work environment
§ Monitor subordinates’ performance and provide formal and informal feedback and appraisal in order to maximize efficiency
Skills:
Network/Web/Mobile/Wireless pentesting
MITRE ATT&CK
OWASP
Competencies
Technical Writing
Automation/ Scripting and Integration
Vulnerabilities Assessment
Penetration Testing
Secure Programming
Technology Advising/Consulting
Qualifications:
Bachelor’s degree in Engineering or related technical discipline
Certifications:
OSCP
GMOB
GWAPT
GPEN
eWAPTX
Experience:
A minimum of 6 years of relevant experience with at least 3 years in a similar role
تعليقات
إرسال تعليق