Dear Candidate,
We are looking for Cyber Security Analyst - Vulnerability Analys.
Interested candidate can share their profile on
[email protected].
Cyber Security Analyst II (Vulnerability)
As an Infrastructure Vulnerability Analyst you will work as a member of the Infrastructure Vulnerability Management team responsible for reducing the organization's attack surface.
Responsibilities
- Support identification of vulnerabilities by enhancing vulnerability identification at process and technology level.
- Own and manage infrastructure vulnerability scanning process and tools to align with vulnerability identification KPIs.
- Support identification, triaging, assignment and remediation of infrastructure vulnerabilities ensuring that vulnerability management lifecycle is followed.
- Monitor and review container and image scanning capabilities and conduct analysis on vulnerabilities to ensure remediation.
- Work with the CSIRT on the detection and mitigation of incidents.
- Perform validation of moderately to highly complex vulnerability security reports.
- Follow up and mitigate the findings of infrastructure penetration testing assessments and PCI compliance assessments.
- Drive the remediation process to ensure vulnerable assets are patched or remediated with compensating controls within agreed SLAs.
- Proactively research new methods,
tools, and strategies to effectively identify infrastructure vulnerabilities.
Skills Required
- Bachelor's Degree or equivalent experience.
- 3 - 5+ years working in security practices.
- [MANDATORY] Advanced level of understanding of infrastructure vulnerability scanning tools, e.g. network, cloud, container and image scanning solutions.
- [MANDATORY] Experience with implementing and maintaining scanning tools for endpoints, bare-metal, cloud and containers.
- [MANDATORY] Experience with Docker and Kubernetes environments with good understanding of container and image vulnerability remediation processes.
- Relevant industry certification i.e. SANS, ISACA, ISC2 (a plus).
- Knowledge of Infrastructure vulnerability management and scanning tools like Tenable, Rapid7, Qualys or similar.
- Knowledge of the Infrastructure vulnerability management lifecycle, including vulnerability assessment, prioritization, remediation, and validation.
- Knowledge of container security, including Docker and Kubernetes infrastructure, with an understanding of how to identify and remediate vulnerabilities within these environments. Hands-on experience is preferred, however, solid theoretical knowledge is a minimum requirement
Regards,
Anjali Bhadra
📌 Cyber Security Analyst - Vulnerability Analyst (Bengaluru)
🏢 Norwin Technologies
📍 Bengaluru