Security Analyst / Pen Tester

Mindlance
Dulles, United States of America
1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Junior

Job location

Dulles, United States of America

Tech stack

Java
JavaScript
Microsoft Windows
Apple Mac Systems
Software System Penetration Testing
Big Data
Static Program Analysis
Computer Security
Linux
Perl
Information Systems Security Architecture Professional
Python
Network Security
Open Web Application Security
Parsing
Ruby
Software Engineering
SQL Injection
Software Vulnerability Management
Web Applications
Scripting (Bash/Python/Go/Ruby)
Computer Network Technologies
Cross-Site Scripting (XSS)
Nessus
Nexpose
Qualys
Vulnerability Analysis

Job description

The Technical Security Analyst position is within client's IT Security group whose mission is to deliver information security solutions and services to protect client information assets, computing infrastructure, applications, and data. The Analyst will work within the vulnerability management team helping to identify and mitigate risks against client. The ideal candidate will have great interest in information security, has hands-on security engineering experience, and be able to come up with creative and unique solutions to security- related problems.

The Analyst will perform technical security engineering activities including the following:

  • Perform vulnerability scan, analysis, validation and remediation activities.
  • Perform network and application penetration testing.
  • Validate vulnerabilities discovered through code analysis.
  • Classify and prioritize the risk of new vulnerabilities according to the specifics of client environment's risk level, mitigating factors, and assessment of the impacts of internal and external threats.
  • Engineer application, system and network security solutions to meet security requirements for varied operating environments.
  • Research and assess new threats, vulnerability security trends and security alerts, recommend remedial action.
  • Work with customers to oversee remediation of identified security issues.
  • Perform technical and non-technical compliance activities.
  • Provide security subject matter expertise to client product teams including developers and system administrators.
  • Perform security validation for configuration settings on different systems.

Requirements

Hiring manager is seeking candidates with a pen testing background who knows how to test for OWASP Top 10 web application vulnerabilities and is interested in growing their skills., * Bachelor's degree with a minimum of 1 year of information security work experience.

  • A strong interest in the field of information security.
  • Intermediate scripting, system administration or software engineering background (e.g. Python, Ruby, Javascript, Perl, or Java).
  • Fluent in a variety of web application protocols, operating systems and networking technologies.
  • Strong understanding of common network vulnerabilities, OS vulnerabilities (Linux, Windows and OSX), patching and attack patterns.
  • Intermediate understanding of OWASP Top 10 vulnerabilities such as XSS, XSRF, SQL Injection, Cookie Manipulation among others.
  • Strong analytical, problem solving and engineering skills.
  • Good written and verbal communication skills.
  • Solid organizational skills and strong customer service skills.
  • Experience with parsing / analysis of large data sets (e.g. vulnerability scan results).

Desired Qualifications

  • Certified Information Systems Security Professional (CISSP).
  • Certified Ethical Hacker (CEH)
  • Familiarity with Enterprise Vulnerability Management tools such as Rapid 7 Nexpose, Nessus and Qualys. Familiarity with Amazon Web Services (AWS) security.

Apply for this position