CyberSecurity_Vulnerability_Analyst
190 - 210 PLN/ godz.B2B
SeniorFull-time·B2B
#399842·Dodano 5 dni temu·18
Źródło: ITFSTech Stack / Keywords
CybersecurityWiresharkSDLCOWASP
Firma i stanowisko
The position is offered by ITFS, located in Warsaw with a hybrid work model (up to 20% onsite, 80% remote). It involves work on a security-related project requiring extensive cybersecurity vulnerability analysis experience and certifications.
Wymagania
- Higher education (minimum bachelor's degree).
- At least 8 years of professional IT experience, including minimum 5 years in cybersecurity vulnerability analysis roles.
- Possession of at least 3 certifications from: GCED, GPPA, GCWN, GCUX, GCCC, SSCP, GPEN, GXPN, GMOB, NDS, ECSA, GSNA, GSEC, SCPO, or internationally recognized equivalents.
- Possession or readiness to obtain CONFIDENTIEL UE/EU CONFIDENTIAL security clearance.
- Practical knowledge and use of security tools like Tenable vulnerability management suite, NMAP, Wireshark, BurpSuite.
- Skills in vulnerability identification, exploitation, risk assessment, and ethical hacking.
- Experience coordinating, designing, and conducting penetration tests.
- Knowledge of secure software development lifecycle (SDLC), OWASP standards, and secure code reviews.
- Ability to analyze systems, computer networks, and OS for identifying vulnerabilities and evaluating security controls.
- Experience implementing protections against common exploits, especially web applications.
- Experience administering, configuring, and integrating security solutions with infrastructure (vulnerability management platforms, WAF, EDR).
- Proficiency in writing vulnerability reports, patch management, and creating security procedures and policies (information protection and data privacy).
- English at minimum B2 level (certified or readiness for testing).
Nice to have:
- Possession of CISSP certification (accepted as one of the required three certificates).
Obowiązki
ZAKRES OBOWIĄZKÓW:
- Receiving, validating and triaging vulnerability reports for hardware and software based on exposure level and impact analysis.
- Technical analysis of vulnerabilities through source code review, reproducing issues in test environments, and using tools like debuggers.
- Proactive vulnerability scanning, penetration testing, continuous monitoring, and processing security alerts.
- Performing forensic analysis in response to security incidents.
- Developing remediation strategies, mitigation instructions, and overseeing patch management processes.
- Handling vulnerabilities without ready patches (e.g., zero-day) including coordination with vendors and technical experts.
- Evaluating security controls, architecture, and configurations of new applications and systems.
- Verifying technical compliance of systems against security gold configurations and participating in baseline standards development.
- Verifying effectiveness of remediation actions and preventive mechanisms.
- Communicating identified threats and remediation paths to organizational units.
- Preparing detailed audit and security test reports with recommendations for technical teams.
- Creating dashboards and reporting KPIs related to system patching levels.
- Monitoring service levels (SLAs) and reporting current team activities.
Benefity
- Access to medical and sports packages.
- Free accounting services (up to 3 entries monthly).
- Work on an interesting and developing project.
- Transparent collaboration conditions in a company with a stable market position.
Karta sportowa
Opieka zdrowotna
ITFS
75 aktywnych ofert