Principal Consultant, Penetration Testing & Vulnerability Assessment

 

About the job

PURPOSE:


  • Jobs at this level are responsible for carrying out a range of cybersecurity penetration testing and vulnerability assessment activities including supervising assessment of threats and vulnerabilities, identification of deviations from required and/or acceptable configurations, and evaluation of existing level of risk to recommend appropriate remediation measures.




Key Responsibilities:


Organizational Responsibilities

Follow all relevant cybersecurity penetration testing and vulnerability assessment policies, processes and standard operating procedures so that work is carried out in a controlled and consistent manner.

Operational Responsibilities

  • Supervise the day-to-day activities of subordinates to ensure that work processes are implemented as designed and in compliance with established standards and procedures
  • Establish service level agreements with relevant stakeholders as per the SITE’s policies and procedures
  • Conduct non-intrusive penetration testing and vulnerability assessment in clients’ industrial control networks and systems
  • Supervise the identification and evaluation of cybersecurity vulnerabilities in physical devices, and mobile devices analysis for indicators of compromise
  • Supervise the identification and evaluation of cybersecurity vulnerabilities in applications, network devices, and infrastructure software
  • Oversee vulnerability scanning on information systems to ensure protection has been put in place on those systems
  • Supervise the assessment of current technology infrastructure to identify key risks areas, and ensure adequate level of control are in place to address those risks
  • Assist in designing social engineering campaigns to detect vulnerabilities related to the human factor
  • Ensure proper coordination of phishing campaigns to determine employees’ awareness level against phishing attacks
  • Supervise the development of a collaborative, cloud-based penetration testing environment to allow dynamic creation of attack scenarios, and generation of reports
  • Supervise proper tasks allocation across team members and adherence to standards
  • Coordinate cross-functionally to accomplish assigned tasks
  • Support in developing related high-level reports for reporting and decision-making purposes

People Management Responsibilities

§ Develop and motivate subordinates to ensure transfer of know-how and maintain a positive work environment

§ Monitor subordinates’ performance and provide formal and informal feedback and appraisal in order to maximize efficiency

Skills:


Network/Web/Mobile/Wireless pentesting

MITRE ATT&CK

OWASP


Competencies


Technical Writing

Automation/ Scripting and Integration

Vulnerabilities Assessment

Penetration Testing

Secure Programming

Technology Advising/Consulting



Qualifications:


Bachelor’s degree in Engineering or related technical discipline


Certifications:


OSCP

GMOB

GWAPT

GPEN

eWAPTX


Experience:

A minimum of 6 years of relevant experience with at least 3 years in a similar role

https://www.linkedin.com/jobs/view/2980754764/?refId=LYdiHCLbaKv%2FyFkT8wlxbw%3D%3D&trackingId=9F2nmFMYBWDzkpwLZFF8KA%3D%3D

تعليقات

المشاركات الشائعة من هذه المدونة

Possession Officer at Riyadh Metro Project.- Saudi National

Documentation Officer