Internal Penetration Testing: Perform regular, deep-dive manual penetration tests on our web applications. You must be able to go beyond automated scans to find complex logic flaws, session management issues, and bypasses.
Infrastructure Hardening: Conduct recurring vulnerability assessments of our servers (Windows/Linux) and networking devices.
Remediation & Collaboration: Work directly with our development team to provide technical "how-to" guidance on fixing vulnerabilities, such as implementing mTLS, securing API endpoints, and hardening database configurations (SQL Server/PostgreSQL).
...
Prioritize and track remediation efforts for identified vulnerabilities, collaborating with relevant teams to ensure timely resolution.
Stay abreast of emerging threats, vulnerabilities, and attack techniques to enhance VAPT strategies.
Establish and maintain robust security governance frameworks, policies, standards, and procedures in alignment with industry best practices (e.g., ISO 27001, NIST, internal compliance requirements).
...
Provide insights into areas of potential vulnerability and recommend corrective action.
Keep up to date with industry trends, regulatory changes and emerging cybersecurity threats.
Plan, execute and manage the risk-based audit assignments as per the Audit Plan to ensure the audit fulfil the approved audit objectives and audit scope and the standards as prescribed in the Audit Methodology.
...
Prioritize and track remediation efforts for identified vulnerabilities, collaborating with relevant teams to ensure timely resolution.
Stay abreast of emerging threats, vulnerabilities, and attack techniques to enhance VAPT strategies.
Establish and maintain robust security governance frameworks, policies, standards, and procedures in alignment with industry best practices (e.g., ISO 27001, NIST, internal compliance requirements).
...
Internal Penetration Testing: Perform regular, deep-dive manual penetration tests on our web applications. You must be able to go beyond automated scans to find complex logic flaws, session management issues, and bypasses.
Infrastructure Hardening: Conduct recurring vulnerability assessments of our servers (Windows/Linux) and networking devices.
Remediation & Collaboration: Work directly with our development team to provide technical "how-to" guidance on fixing vulnerabilities, such as implementing mTLS, securing API endpoints, and hardening database configurations (SQL Server/PostgreSQL).
...
Experience with cybersecurity and GRC areas such as risk assessments, control testing, incident and vulnerability management; exposure to tools (e.g. SIEM, EDR/XDR, GRC platforms) is a plus.
Strong analytical, documentation, and communication skills, with the ability to translate technical risks into business impact and work effectively with stakeholders.
Assist with tickets relating to whitelisting, blocking, and reputation management by validating IPs, domains, URLs, hashes, and certificates against threat intelligence sources; liaise with users for additional details and coordinate implementation within security controls.
Examine alerts from various security monitoring tools (SIEM, EDR, NDR, SOAR, Threat Intelligence Platforms), perform triage and scoping using intelligence‑driven analysis; execute in‑depth intrusion analysis, cyber forensics, malware analysis, and basic reverse engineering, escalating high‑risk or campaign‑level threats as necessary.
Perform proactive threat hunting activities by leveraging threat intelligence hypotheses, MITRE ATT&CK mapping, historical incident data, and adversary emulation techniques to uncover stealthy or previously undetected threats.
...