¡Activa las notificaciones laborales por email!

Penetration tester with security clearance

Wlgroup

Barcelona

Presencial

EUR 45.000 - 65.000

Jornada completa

Hoy
Sé de los primeros/as/es en solicitar esta vacante

Genera un currículum adaptado en cuestión de minutos

Consigue la entrevista y gana más. Más información

Descripción de la vacante

An international intergovernmental organization in Barcelona is seeking a Penetration Testing Specialist to conduct security assessments and provide technical insights. The ideal candidate will hold a Bachelor's degree in a technical subject and have at least 3 years of experience in penetration testing. Strong knowledge in web application security, infrastructure security, and proficiency in scripting languages like Python are essential. Fluency in English is required. Competitive compensation and opportunities for professional development included.

Formación

  • 3 years post-related experience in IT.
  • Knowledge in system and network administration of UNIX and Windows systems.
  • Ability to evaluate risks and formulate mitigation plans.

Responsabilidades

  • Conduct penetration testing including Web and infrastructure.
  • Participate in meetings to identify testing requirements.
  • Write technical reports in fluent English.

Conocimientos

Web application penetration testing
IT infrastructure penetration testing
Network security architecture design
Assessing security vulnerabilities
Scripting skills in Python
Fluent English skills

Educación

Bachelor of Science (BSc)

Herramientas

Penetration testing tools
Descripción del empleo

Would you like to join the leading international intergovernmental organization?

The NCIA NATO Cyber Security Centre (NCSC) is responsible for planning and executing alllifecycle management activities for cybersecurity. In executing this responsibility, NCSC providesspecialist cyber security-related services covering the spectrum of scientific, technical,acquisition, operations, maintenance, and sustainment support, throughout the lifecycle ofNATO Information Communications and Technology (ICT).Within the NCSC, the Penetration Testing Section plays a critical offensive security role. They conduct tailored vulnerability assessments, penetration testing, and red teaming activities against NATO networks throughout their entire lifecycle.

Responsibilities
  • Providing Web, infrastructure and application level penetration testing, including but notlimited to COTS software and NOTS/GOTS software (NATO/Government off the Shelf),following clearly defined methodologies.
  • Participating in kick-off meetings with stakeholders and technical points of contact inorder to identify requirements for testing.
  • Following the documented procedures and workflows outlined by the technical leads.
  • Attending team meetings if required.
  • Writing technical reports in fluent English, following defined templates and ReportingTools.
  • Briefing, at both executive and technical levels, on security reports and testing outcome,including at flag officer level.
  • In case of new vulnerabilities detected for COTS software, following the Responsible Disclosure Process and following-up with vendors and stakeholders.
  • Providing security design reviews to ensure compliance with NATO policies anddirectives.
  • In co-ordination with the Technical Lead of the Penetration testing team, ensuringproactive collaboration and coordination with internal and external stakeholders.
  • Staying abreast of technological developments relevant to the area of work.
  • Performing any other duties as may be required.
We are happy to hear from you if you have:
  • Bachelor of Science (BSc) degree at anationally recognised/certified university in a technical subject with substantial InformationTechnology (IT) content and 3 years post-related experience.
    • Web application penetration testing
    • IT infrastructure penetration testing
    • Network security architecture design
    • Assessing security vulnerabilities within OS, software, protocols & networks
    • Researching and evaluating security products & technologies
    • Knowledge in system and network administration of UNIX and Windows systems
    • Use of penetration testing tools, techniques, and recognized testing methodologies
    • Scripting skills in at least one of the following: Python, Go, PowerShell, shell (bash, ksh,csh)
    • Technical knowledge in system and network security, authentication and security protocols, cryptography, application security, as well as, malware infection techniques and protection technologies.
    • Ability to evaluate risks and formulate mitigation plans.
    • Proven ability to brief at executive level on security findings, reports and testing outcome.
    • Proven ability to write clear and structured technical reports, including executivesummary, technical findings and remediation plan for several different audiences.
  • Fluent English skills(verbal and written).
  • Desirable Experience and Education:
    • Professional qualifications: OSCP, OSCE, OSWE, GPEN, CREST Certified Web ApplicationTester, GXPN, GWAPT or equivalent
    • Familiarity with risk analysis methodologies.
    • Prior experience of working in an international environment comprising both militaryand civilian elements.
    • Knowledge of NATO organization, internal structure and resultant relationships.

If you've read the description and feel this role is a great match, we'd love to hear from you! Click "Apply for this job" to be directed to a brief questionnaire. It should only take a few moments to complete, and we'll be in touch promptly if your experience aligns with our needs.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra un archivo en formato PDF, DOC, DOCX, ODT o PAGES de hasta 5 MB.