job description
- hands-on experience with key components of cybersecurity including penetration testing, red teaming, vulnerability management, network & infrastructure security, managed detection and response.
- expert knowledge and practical experience with common frameworks, standards and methodologies used such as mitre, owasp, nist cybersecurity, is /2.
- practical experience with conducting penetration tests and executing red team engagements.
- possession/working towards the following certifications: cissp, cisa cism, oscp, gpen, gwapt
- experience with dark web monitoring and crawlers
- prior experience or expertise performing red team exercises will be a plus
- experience in writing proof-of-concept exploits and creating custom payloads and modules for common ethical hacking frameworks and tools
- well versed in system exploits (. buffer overflows, pth attacks, windows authentication framework etc.), network exploitation (. vlan hopping) or web application exploitation
- well versed with security tools & frameworks like metasploit, core, canvas etc.
- should be able to formulate enterprise security strategy, security policy development
- should be able to face the security audit and provide responses
- identify and manage access control strategy
- need to own and enhance the project security architecture
- experience in penetration testing, va, cyber security testing.
- is a single point of contact for the security framework implementation and maintenance
- should have experience in application security tools and interpretation of reports
- should be aware of top 20 owasp vulnerabilities and ways to overcome them.
- should have experience on load balancers from radware & f5
- should have implementation experience for ddos and waf
- should be able to implement robust solutions to overcome the security issues.