Job Description:
As a Cybersecurity Specialist, you will play a critical role in protecting the organization’s digital assets through thorough security testing, vulnerability detection, and the implementation of best security practices. You will work closely with cross-functional teams to identify and mitigate system weaknesses, ensuring that IT infrastructure remains resilient against evolving cyber threats.
Responsibilities:
- Perform security testing activities, including penetration testing and vulnerability assessments on web applications, network infrastructure, and cloud environments.
- Design and maintain both automated and manual security testing strategies to ensure comprehensive coverage across critical systems, applications, and services.
- Configure and manage security tools and environments, such as vulnerability scanners, SIEM, firewalls, IDS/IPS, and other relevant monitoring technologies.
- Create detailed technical reports and risk assessments, outlining identified vulnerabilities, potential impacts, and actionable remediation aligned with industry best practices.
- Collaborate with DevOps, development, and infrastructure teams to integrate secure coding practices throughout the software development lifecycle (SDLC), in line with standards such as OWASP, ISO 27001, and NIST.
- Continuously monitor for anomalies and conduct post-exploitation analysis to simulate real-world attack scenarios and evaluate the effectiveness of defensive mechanisms.
- Stay current with emerging threats, tools, and techniques, and apply this knowledge to enhance internal testing methodologies and improve overall security posture.
Requirements:
- Proven experience in security testing, including penetration testing and vulnerability assessments on web applications, networks, or cloud infrastructure.
- Strong understanding of information security standards and frameworks such as OWASP Top 10, NIST, and ISO 27001, with practical implementation experience.
- Ability to conduct secure code reviews and identify vulnerabilities in popular CMS platforms such as WordPress, Joomla, and Drupal.
- Proficiency with industry-standard security tools like Burp Suite, Nmap, Metasploit, Wireshark, and related frameworks.
- Solid understanding of network protocols, system architecture, and infrastructure security best practices across diverse environments.
- Hands-on experience with scripting or programming languages (e.g., Python, PHP, Java, or Shell scripting) for automating security tasks and creating custom test scripts.
- Security certifications such as OSCP, CEH, or CISSP are highly desirable and considered a significant advantage.