Cybersecurity Consultant
Role details
Job location
Tech stack
Job description
- Conducts security assessments that can be multi-faceted for a wide variety of assigned clients
- Defines the scope for security testing assignments
- Creates quality assurance security test reports and other documentation as needed
- Works with clients to develop appropriate remediation plans
- Provides clients with exceptional service in a professional, courteous and timely manner
- Provides technical support as a subject matter expert in the sale of security testing assignments on an as needed basis
- Provides thought leadership and direction for the Information Security practice on malware, attack vectors and methods to protect against threats
- Teams up with colleagues in other lines of services in support of client needs for Information Security services
- Stays up-to-date on current tools, technologies and vulnerabilities to incorporate into testing practices
- Other related duties as assigned
Requirements
Linux, English, Information Systems, Windows, Communication Skills, Computer Science, * Degree in Computer Science, Information Systems, Engineering or related major from an accredited University or College Diploma equivalent
- Experience performing vulnerability assessments and/or penetration tests would be preferred
- Application and/or infrastructure penetration testing experience above and beyond running automated tools
- A good understanding of Linux, Windows and network security skills
- Excellent written and oral communication skills in English
- Ability to meet deadlines and deliver a high-quality product (reports)
- Strong attention to detail
- Ability to work both independently and in a team environment.
FAMILIAR WITH (IF NOT QUALIFIED IN) TEST SUITES SUCH AS:
- Nessus
- MetaSploit
- Burp Suite
- Kali
- NMap
- Fortify
- Acunetix
Certifications - One or more of the following certifications are considered an asset:
- EC-Council Certified Ethical Hacker (CEH)
- EC-Council Licensed Penetration Tester (LPT)
- GIAC Certified Penetration Tester (CPEN)
- IACRB Certified Penetration Tester (CPT)
- Offensive Security Certified Professional (OSCP)
- CREST Registered Tester (CRT)
- CREST Infrastructure Certification
- CESG CHECK Team Leader
- CESG CHECK Team Member
- Tiger Scheme Senior Security Tester
- Tiger Scheme Qualified Security Tester
- Any other recognized penetration testing certification/accreditation
PCI ASV
- CREST recognized penetration testing certification/accreditation (CREST Certified Tester (CCT) or CHECK Team Leader (CTL)
- Experience developing custom scripts or tools used for vulnerability scanning and identification
- Familiarity with threat modelling and security design review methodologies
- Support team technical development (e.g. through service development or research) and contribute to company technical processes overall
- Development and/or source code review experience in C/C++, C#, VB.NET, ASP, PHP, or Java and/or Fortify, Veracode, Brakeman and/or IDA Pro
- Experience with physical security testing, phishing and social engineering techniques.
- Experience with mobile applications such as Android DeBug Bridge (ADS), OWASP ZAP, Drozer, Mobile Security Framework (MobSF), Smartphone Pentest Framework (SPF), Burp Suite, Android SDK, Friday, Cydia and/or IDB
Benefits & conditions
- 25 days holiday per year plus public holidays
- Pension plan
- Annual discretionary bonus
- Monthly events
- Opportunity to work in a diverse work environment with global colleagues
This job description should not be interpreted as all-inclusive; it is intended to identify major responsibilities and requirements of the job. The incumbent may be requested to perform other job-related task and responsibilities than those stated above. GLI is an Equal Opportunity Employer All qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status