> job detail
A
👽Other
Cybersecurity Vulnerability Analyst
Arhaus Inc Class A · Warsaw, Masovian Voivodeship, Poland
// classified as
Other (Adjacent or hard to classify.)
posted
1d ago
location
Warsaw, Masovian Voivodeship, Poland
languages
—
tools
—
> description
Job Description
- Receiving information and reports about hardware and software vulnerabilities; analysing the nature, mechanics, and effects of the vulnerabilities; and developing response strategies for detecting and repairing the vulnerabilities.
- Proactively managing vulnerabilities by performing vulnerability assessments, penetration tests and reviewing the technical security compliance (deviation from a baseline configuration) of systems and services.
- Managing response to disclosed vulnerabilities for which no countermeasure is yet available.
- This service can involve communicating with vendors, other CSIRTs, technical experts, consultant members, and the individuals or groups who initially discovered or reported the vulnerability.
- Evaluates results of security audits and tests, security findings, priorities, plans, and implements remediation controls.
- Provides forensic analysis in response to information security incidents.
- Assesses security controls of new applications to establish compliance level and appropriate configuration.
- Performing vulnerability watch.
- Processing of incoming vulnerability warnings, alerts and reports.
- Oversee the management of known vulnerabilities through established processes and procedures.
- Triage based on verification, level of exposure and impact assessment.
- Analysing and examining vulnerabilities in hardware or software.
- Validating the existence of suspected vulnerabilities by determining where they are located and how they can be exploited.
- Reviewing source code, using a debugger to determine where the vulnerability occurs, or trying to reproduce the problem on a test system.
- Notifying the various parts of the Agency about the vulnerability and shares information about how to fix or mitigate the vulnerability.
- Verifying that the vulnerability response strategy has been successfully implemented.
- Performing regular vulnerability scans of system and applications, writing reports including recommendations for improvements and following-up the remediation process for identified vulnerabilities.
- Providing regular reports and dashboards (based on KPIs) to monitor security improvements.
- Performing penetration tests and writing reports including recommendations for improvements.
- Reviewing the technical security compliance of systems against defined security baselines (gold configuration), writing reports and following-up the remediation process for identified non-compliance.
- Participating in the definition of security baselines.
- Provide activity reports to management to demonstrate service SLA and service quality.
Qualifications
- Bachelor's degree plus 8 years of IT relevant professional experience
- Minimum 5 years of experience at similar position
- Active EU Security Clearance is required
- Minimum English language skills (CEFR) : B2
- Knowledge of systems development life cycle
- Knowledge of operating systems security
- Knowledge of computer networks security
- Knowledge of security controls
- Knowledge of offensive and defensive security practices
- Knowledge of secure coding practices
- Possesses hands-on experience in ICT in the role of Cybersecurity Vulnerability Analyst
- Knowledge of system security vulnerabilities, threats and exploit mechanisms, penetration testing, remediation techniques and risk analysis methodologies
- Knowledge of OWASP family standards
- Practical knowledge of designing and performing security tests
- Practical knowledge of Tenable vulnerability management suite, NMAP, Wireshark, BurpSuite
- Analytical mind, attention to details and an ability to pick things up quickly; problem solving skills
- Document, report, present and communicate with various stakeholders
- Develop codes, scripts and programmes
- Identify and exploit vulnerabilities
- Conduct ethical hacking
- Think creatively and outside the box
- Identify and solve cybersecurity-related issues
- Communicate, present and report to relevant stakeholders
- Use penetration testing tools effectively
- Conduct technical analysis and reporting
- Decompose and analyse systems to identify weaknesses and ineffective controls
- Review codes, assess their security, integrate cybersecurity solutions to the organisation's infrastructure
- Configure solutions according to the organisation's security policy
- Assess the security and performance of solutions
- Develop and test secure code and/or scripts
- Identify and troubleshoot cybersecurity-related issues
Specific requirements:
- Experience in vulnerabilities analysis
- Knowledge of risk assessment in the context of given vulnerability and its environment
- Experience in coordination and execution of PenTests
- Experience in implementing protections against the most common types of exploits for web apps
- Proficient in writing reports covering vulnerabilities and patch management
- Experience in reviewing current security controls and proposing improvements
- Experience in writing security procedures/policies with emphasis in information protection and data privacy
- Experience in administering security solutions – Vulnerability platform, WAF, EDR
- Innovative approach to new technologies
Required certificates (At least 3 certifications among):
- GCED (GIAC Certified Enterprise Defender)
- GPPA (GIAC Certified Perimeter Protection Analyst)
- GCWN (GIAC Certified Windows Security Administrator)
- GCUX (GIAC Certified UNIX Security Administrator)
- GCCC (GIAC Certified Critical Controls)
- SSCP (ISC² Certified Systems Security Practitioner)
- GCWN (GIAC Certified Windows Security Administrator)
- GCUX (GIAC Certified UNIX Security Administrator)
- GCCC (GIAC Certified Critical Controls)
- GPEN (GIAC Certified Penetration Tester)
- GXPN (GIAC Certified Exploit Researcher and Advanced Penetration Tester)
- GMOB (GIAC Certified Mobile Device Security Analyst)
- NDS (EC-Council Certified Security and Vulnerability Assessor)
- ECSA (EC-Council Certified Security Analyst)
- GSNA (GIAC Certified Systems and Network Auditor)
- GSEC (GIAC Certified Security Essentials)
- ECSA (EC-Council Certified Security Analyst)
- SCPO (SABSA Certified Security Operations & Service Management Practitioner)
- ECSA (EC-Council Certified Security Analyst)
- or for any listed above, an equivalent alternative certification recognized internationally (subject to acceptance as a valid credential by the Contracting Authority).
Company Description
Arηs Group, Part of Accenture, specializes in the management of complex public sector IT projects, including systems integration, informatics and analytics, solution implementation and program management. Our team helps lead clients through digital and information systems design, bringing expertise in a variety of areas ranging from software development, data science and security management to machine learning, cloud, and mobile development. Arηs Group was acquired by Accenture in July 2024.