More jobs:
Job Description & How to Apply Below
Our client is looking for Intermediate Security Analyst to support a banking client with Pentesting, purple teaming & TTX logic, and programming/scripting.
Overview:
Advanced Penetration Testing:
Perform comprehensive, hands-on penetration tests (Black Box, Grey Box, White Box) on web applications, APIs, network infrastructure, and cloud environments, simulating real-world attack scenarios using tools like Burp Suite, Postman, and Kali Linux.
Must Have's:
:
Proven, hands-on experience in exploiting vulnerabilities in modern systems, including OWASP Top 10, API security flaws (CWE/CVE), and cloud misconfigurations (AWS/Azure/GCP)
:
Proficiency in at least one scripting language (
Python, Power Shell
) for automation, exploit development, and custom tool creation.
Responsibilities:
Design and execute targeted operations to test the company's security monitoring, detection, and response capabilities. Partner closely with the Blue Team to validate fixes and assist in designing preventative security controls.
Design and build technically-grounded attack patterns and "injections" for strategic, company-wide enterprise crisis simulations and focused, operational TTXs.
Lead the creation of detailed Statements of Work (SOWs) and Rules of Engagement (ROEs) for third-party penetration testing vendors, managing the full testing lifecycle through final report review and risk acceptance.
Act as a bridge between the technical security team and non-cyber teams, clearly articulating technical vulnerabilities as business risks and driving remediation efforts with non-technical stakeholders.
Produce clear, detailed, and technically accurate reports outlining vulnerabilities, the exploit path, and risk-rated recommendations. Perform peer reviews of reports from other penetration testers to ensure accuracy and reproducibility.
Develop and maintain high-quality operational documentation, including Standard Operating Procedures (SOPs), Job Aids, and technical runbooks for testing methodologies and post-exercise remediation processes.
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×