Responsible for identifying, analyzing, and mitigating vulnerabilities in the company's systems and networks through advanced penetration testing.
Following points capture the key responsibilities of the individual:
- Red Team Lead: Plans and orchestrates simulated cyber-attacks.
- Penetration Testers: Conduct scheduled attacks on your infrastructure to discover vulnerabilities.
Automation: Automated investigation and Remediation
Scope of Work
Simulated telco cyber-attack against applications (Web/Mobile/API) to check for attempted breaching of any number of application systems, (e.g., application protocol interfaces (APIs), frontend/backend servers) to uncover vulnerabilities.
Vulnerability Assessment
Manage third party vendor for defining, identifying, classifying and prioritizing vulnerabilities in computer systems, applications and network infrastructures at Telco Areas
Reporting and Documentation
Provide detailed reports on findings and recommend remedial actions.
Collaborate with IT Teams
Work closely with IT staff to implement security measures.
Qualifications:
- Minimum bachelor's degree (Information Technology/ Electrical Engineering/Telecommunication Engineering, Computer Science, Communications, Marketing, Information Security, Business, Technical).
- C|EH - Certified Ethical Hacker V12
- Security certificates such as OSCP, CISSP, CISA, CISM, GIAC, CISA, SANS, and ISO 27001 Lead Implementor/Lead Auditor, etc.
- Familiar with OWASP Top 10 Web and API
- Familiar with XML and JSON data format, HTTP protocol, and REST API
- Ability to analyze and identify actions to be taken.
- Honesty and high-integrity character
- Working well under preasure
- Good communication and influence skill
- Strong understanding of all Information Security Domains
- Sound understanding of businesses supported and security principles and policies.
- Knowledge of network, system, and application monitoring technologies
- Exemplary networking and negotiation skills
Experience:
- 5-7 years in vulnerability testing, with expertise in penetration testing and vulnerability assessment.
- Experience with cloud security, including AWS, Azure, or Google Cloud Platform.
- Hands on of DevSecOps practices and integrating security into CI/CD pipelines.
- Familiarity with containerization and orchestration tools like Docker and Kubernetes.
Skills:
- Operational Management
- Software Engineering
- Data Knowledge
- Strong verbal and written communication skills (fluency in English is required)
- Having basic knowledge on risk mitigation and information security theories, technique and principles.
- Good communication skill both writing and verbally to be able to work together with all employees in the company.
- Ability to convey message in clear, concise and simple way to various employees in the company.
- Ability to deliver and develop presentation in front of different audience and answering their questions.
- Ability to manage, organize and do multiple task to meet tight deadlines.
- Have integrity, confidentiality and independence.
- Ability to move forward and flexibility under various environment that continue to change.
- Databases and operating systems
- Information security fundamentals
- Data security fundamentals and best practices with prior responsibilities of protecting information assets.
- Security technologies
- Best practices and industry standards with prior responsibilities of protecting information asset