jobs in T7 Intelligent Resources

T7 Intelligent Resources Hiring! Full Time Vulnerability Assessment Analyst in Federal Territory - Ricebowl

Vulnerability Assessment Analyst

Undisclosed

KL City, Federal Territory

Share
Save

Working Location

  • Kuala Lumpur Federal Territory Malaysia

Job Description

Responsibilities

VULNERABILITY ASSESSMENT ANALYST



ROLE PURPOSE:

To be part of the Cyber Threat team that conducts vulnerability assessment and penetration testing across the bank’s assets (applications and infrastructure) to ensure the confidentiality, integrity, and availability of information is kept intact through vulnerability assessment and penetration testing.


KEY RESPONSIBILITIES:

  • Conduct in-depth vulnerability assessment and penetration testing across the bank’s assets (application and infrastructure) to identify potential weaknesses and security gaps. The vulnerability assessment is consisting of application security testing (web, mobile, API) and infrastructure security testing (IT and OT servers, network devices, cloud, etc.)
  • Utilizing automated scanning tools and manual testing techniques to discover vulnerabilities in the bank’s assets. Experience using Tenable products, Burp Suite, Qualys and native security scanner in cloud provider (AWS, Azure, OCI) would be an advantage.
  • Identifying and categorizing vulnerabilities based on their potential impact and likelihood of exploitation to prioritize remediation efforts effectively.
  • Produce and deliver vulnerability and exploit information, their potential impact and suggested remediation strategies in the form of a professional security assessment report.
  • Provide actionable recommendations and remediation guidance for addressing identified vulnerabilities in a timely and effective manner, and coordinate with the related stakeholders for mitigation. Conduct meetings to communicate the findings and implications to the related stakeholders, if required.
  • Perform analysis to validate justifications for false positives, operational requirements, and risk adjustments.
  • Perform proactive research to identify and understand new threats, vulnerabilities and exploits.
  • Excel as both a self-directed individual contributor and as a member of a team.
  • Provide recommendations to optimize processes and procedures related to enterprise security scanning solutions
  • Provide periodic reports detailing scan success, remediation efforts, and vulnerability trends.
  • Experience in the administration of vulnerability scanners and vulnerability management tools, e.g., Tenable (Nessus, SC, OT and IE), Burp Suite (Pro and Enterprise), Qualys, ServiceNow Vulnerability Response and cloud native scanner (in AWS, Azure, OCI) would be an advantage.



REQUIREMENTS:

  • Academic Qualifications: A degree in Computer Science or Information Technology.
  • Licence / Certification: Relevant cyber security certifications e.g., Certified Ethical Hacker (CEH), Offensive Security Certified Professional
  • (OSCP) or GIAC Web Application Penetration Tester (GWAPT)
  • Experience: Minimum 2 years working experience in application & infrastructure security testing, and penetration testing. At least 1 year
  • Working experience in administration for Tenable, Qualys, Burp Suite, or other vulnerability assessment tools would be an advantage.
  • Solid understanding of OWASP Top 10, OWASP ASVS, CVSS, CVE/CWE, NIST, RMIT, etc.
  • Proven experience in code review and vulnerability assessment.
  • Strong understanding of software lifecycle and methodologies
  • Knowledge of secure coding practices and common security vulnerabilities.
  • Familiarity with security testing tools, such as dynamic/interactive/static analysis scanners, infrastructure security scanners, and penetration testing frameworks
  • Excellent analytical and problem-solving skills.

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More