The Senior Security Engineer (Blue) will be responsible for:
Conduct intelligence and threat-driven security assessments of critical systems, applications, and networks to pinpoint security vulnerabilities, subsequently communicating the potential implications of these vulnerabilities to system/service owners.
Conducts impartial and thorough assessments, yielding actionable security recommendations customized to the specific environment under evaluation.
Identify and validate security vulnerabilities, conducting network mapping and analysis, performing vulnerability assessments, conducting penetration testing on network filters and security countermeasures, proactively seeking threats, responding to incidents, and conducting forensic analysis.
Ensure that security policies and procedures are up to date and aligned with industry standards and regulations. Assist in compliance audits and remediation efforts.
Lead and coordinate incident response efforts when security incidents occur, ensuring swift detection, containment, and eradication of threats
The Successful Applicant
Possess relevant Bachelor's/Master's degree
Relevant certifications such as OSCP, OSCE, GPEN, or GXPN are highly desirable.
Demonstrated success and a comprehensive understanding of ISO/IEC 27001, COBIT, and PCI-DSS.
Expertise in using various security testing tools and frameworks (e.g., Metasploit, Burp Suite, Kali, Metasploit Core Impact etc.) and manual techniques to conduct thorough security assessments.
Proficiency in programming and scripting languages (e.g. Python, Go, Shell Script) to develop custom tools and automation scripts is desirable.
Strong understanding of network protocols, operating systems, and common security technologies (SIEM, XDR/EDR, firewalls, IDS/IPS, WAFs, etc.).
In-depth knowledge of cybersecurity principles, attack vectors, and defense strategies. Familiarity with threat intelligence and risk assessment methodologies, OWASP, Cloud Security best practices.
Excellent analytical and problem-solving abilities, with a proactive approach to identifying and mitigating security risks.
Effective verbal and written communication skills, with the ability to convey complex technical concepts to both technical and non-technical stakeholders.
Demonstrated ability to work collaboratively in a team environment, sharing knowledge, and supporting collective goals.