Cybersecurity Vulnerability Analyst

Posted 3 Days Ago
Be an Early Applicant
Warsaw, Warszawa, Masovian, POL
Hybrid
Senior level
Information Technology
The Role
Analyze and manage hardware and software vulnerabilities: perform vulnerability assessments, penetration tests and regular scans; triage and remediate findings; coordinate with vendors/CSIRTs; conduct forensic analysis; assess security controls and baselines; administer vulnerability platforms/WAF/EDR; produce reports and KPIs; develop scripts and secure code; write policies and support patch management.
Summary Generated by Built In
Company Description

Arηs Group, Part of Accenture, specializes in the management of complex public sector IT projects, including systems integration, informatics and analytics, solution implementation and program management. Our team helps lead clients through digital and information systems design, bringing expertise in a variety of areas ranging from software development, data science and security management to machine learning, cloud, and mobile development. Arηs Group was acquired by Accenture in July 2024. 

Job Description

  • Receiving information and reports about hardware and software vulnerabilities; analysing the nature, mechanics, and effects of the vulnerabilities; and developing response strategies for detecting and repairing the vulnerabilities.
  • Proactively managing vulnerabilities by performing vulnerability assessments, penetration tests and reviewing the technical security compliance (deviation from a baseline configuration) of systems and services.
  • Managing response to disclosed vulnerabilities for which no countermeasure is yet available.
  • This service can involve communicating with vendors, other CSIRTs, technical experts, consultant members, and the individuals or groups who initially discovered or reported the vulnerability.
  • Evaluates results of security audits and tests, security findings, priorities, plans, and implements remediation controls.
  • Provides forensic analysis in response to information security incidents.
  • Assesses security controls of new applications to establish compliance level and appropriate configuration.
  • Performing vulnerability watch.
  • Processing of incoming vulnerability warnings, alerts and reports.
  • Oversee the management of known vulnerabilities through established processes and procedures.
  • Triage based on verification, level of exposure and impact assessment.
  • Analysing and examining vulnerabilities in hardware or software.
  • Validating the existence of suspected vulnerabilities by determining where they are located and how they can be exploited.
  • Reviewing source code, using a debugger to determine where the vulnerability occurs, or trying to reproduce the problem on a test system.
  • Notifying the various parts of the Agency about the vulnerability and shares information about how to fix or mitigate the vulnerability.
  • Verifying that the vulnerability response strategy has been successfully implemented.
  • Performing regular vulnerability scans of system and applications, writing reports including recommendations for improvements and following-up the remediation process for identified vulnerabilities.
  • Providing regular reports and dashboards (based on KPIs) to monitor security improvements.
  • Performing penetration tests and writing reports including recommendations for improvements.
  • Reviewing the technical security compliance of systems against defined security baselines (gold configuration), writing reports and following-up the remediation process for identified non-compliance.
  • Participating in the definition of security baselines.
  • Provide activity reports to management to demonstrate service SLA and service quality.

Qualifications

  • Bachelor's degree plus 8 years of IT relevant professional experience 
  • Minimum 5 years of experience at similar position 
  • Active EU Security Clearance is required
  • Minimum English language skills (CEFR) : B2
  • Knowledge of systems development life cycle
  • Knowledge of operating systems security
  • Knowledge of computer networks security
  • Knowledge of security controls
  • Knowledge of offensive and defensive security practices
  • Knowledge of secure coding practices
  • Possesses hands-on experience in ICT in the role of Cybersecurity Vulnerability Analyst
  • Knowledge of system security vulnerabilities, threats and exploit mechanisms, penetration testing, remediation techniques and risk analysis methodologies
  • Knowledge of OWASP family standards
  • Practical knowledge of designing and performing security tests
  • Practical knowledge of Tenable vulnerability management suite, NMAP, Wireshark, BurpSuite
  • Analytical mind, attention to details and an ability to pick things up quickly; problem solving skills
  • Document, report, present and communicate with various stakeholders
  • Develop codes, scripts and programmes
  • Identify and exploit vulnerabilities
  • Conduct ethical hacking
  • Think creatively and outside the box
  • Identify and solve cybersecurity-related issues
  • Communicate, present and report to relevant stakeholders
  • Use penetration testing tools effectively
  • Conduct technical analysis and reporting
  • Decompose and analyse systems to identify weaknesses and ineffective controls
  • Review codes, assess their security, integrate cybersecurity solutions to the organisation's infrastructure
  • Configure solutions according to the organisation's security policy
  • Assess the security and performance of solutions
  • Develop and test secure code and/or scripts
  • Identify and troubleshoot cybersecurity-related issues

Specific requirements:

  • Experience in vulnerabilities analysis
  • Knowledge of risk assessment in the context of given vulnerability and its environment
  • Experience in coordination and execution of PenTests
  • Experience in implementing protections against the most common types of exploits for web apps
  • Proficient in writing reports covering vulnerabilities and patch management
  • Experience in reviewing current security controls and proposing improvements
  • Experience in writing security procedures/policies with emphasis in information protection and data privacy
  • Experience in administering security solutions – Vulnerability platform, WAF, EDR
  • Innovative approach to new technologies

Required certificates (At least 3 certifications among):

  • GCED (GIAC Certified Enterprise Defender)
  • GPPA (GIAC Certified Perimeter Protection Analyst)
  • GCWN (GIAC Certified Windows Security Administrator)
  • GCUX (GIAC Certified UNIX Security Administrator)
  • GCCC (GIAC Certified Critical Controls)
  • SSCP (ISC² Certified Systems Security Practitioner)
  • GCWN (GIAC Certified Windows Security Administrator)
  • GCUX (GIAC Certified UNIX Security Administrator)
  • GCCC (GIAC Certified Critical Controls)
  • GPEN (GIAC Certified Penetration Tester)
  • GXPN (GIAC Certified Exploit Researcher and Advanced Penetration Tester)
  • GMOB (GIAC Certified Mobile Device Security Analyst)
  • NDS (EC-Council Certified Security and Vulnerability Assessor)
  • ECSA (EC-Council Certified Security Analyst)
  • GSNA (GIAC Certified Systems and Network Auditor)
  • GSEC (GIAC Certified Security Essentials)
  • ECSA (EC-Council Certified Security Analyst)
  • SCPO (SABSA Certified Security Operations & Service Management Practitioner)
  • ECSA (EC-Council Certified Security Analyst)
  • or for any listed above, an equivalent alternative certification recognized internationally (subject to acceptance as a valid credential by the Contracting Authority).

Skills Required

  • Bachelor's degree plus 8 years of IT relevant professional experience
  • Minimum 5 years of experience in a similar position
  • Active EU Security Clearance
  • Minimum English language skills (CEFR) : B2
  • Knowledge of systems development life cycle (SDLC)
  • Knowledge of operating systems security
  • Knowledge of computer networks security
  • Knowledge of security controls and offensive/defensive security practices
  • Knowledge of secure coding practices and OWASP standards
  • Hands-on experience as a Cybersecurity Vulnerability Analyst (vulnerability analysis, threat/exploit mechanisms)
  • Practical experience designing and performing security tests, penetration testing and ethical hacking
  • Practical knowledge of Tenable vulnerability management suite, Nmap, Wireshark, BurpSuite
  • Experience coordinating and executing penetration tests
  • Experience implementing protections against common web app exploits and administering WAF
  • Experience administering vulnerability platforms and EDR solutions
  • Proficient in writing reports covering vulnerabilities, patch management, and producing KPI dashboards
  • Experience reviewing security controls, proposing improvements, and writing security procedures/policies focused on information protection and data privacy
  • Ability to develop code, scripts, and programs to support testing and remediation
  • Analytical mindset, attention to detail, problem solving, and stakeholder communication/presentation skills
  • Required certifications: at least 3 certifications from the listed GIAC/ISC2/EC-Council/SABSA alternatives (or equivalent accepted)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Luxembourg
1,493 Employees
Year Founded: 2003

What We Do

Arηs Group is a market leader in the management of complex IT projects and systems. Founded in Luxembourg in 2003, we’ve grown organically to encompass 16 entities worldwide with over 2,500 employees in Luxembourg, Belgium, France, Greece, Italy, Portugal, Bulgaria and Jordan. With our focus on getting things done, we help our clients achieve their goals with best-of-breed solutions, superior execution and exceptional services. We offer bespoke software development, data science, infrastructure, digital trust and mobile development to government institutions at national and European level, telecom providers, and financial institutions, among others. Our bold company culture is built around working hard and playing hard, with a flat and agile structure that lends itself to efficiency and employee empowerment. We value our diverse workplace of close-knit teams and provide a place where everyone can be supported to learn and evolve.

Similar Jobs

HERE Technologies Logo HERE Technologies

Senior Data Scientist

Artificial Intelligence • Automotive • Computer Vision • Information Technology • Internet of Things • Logistics • Software
Remote or Hybrid
2 Locations
6000 Employees

Mastercard Logo Mastercard

Manager, Services Business Development - Financial Services (Consulting Focus)

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Warsaw, Warszawa, Masovian, POL
38800 Employees

Capco Logo Capco

Senior Business Analyst

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Poland
6000 Employees

Mastercard Logo Mastercard

Senior Specialist, Loyalty Campaign Operations

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Warsaw, Warszawa, Masovian, POL
38800 Employees

Similar Companies Hiring

Scrunch  Thumbnail
Artificial Intelligence • Information Technology • Marketing Tech • Software • SEO
Salt Lake City, Utah
Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account