The Cyber Security Analyst will perform hands‑on web and network penetration testing and conduct in‑depth security analysis. Responsibilities include vulnerability discovery and validation, exploit testing, security configuration review, producing clear findings and remediation guidance, and carrying out real‑world assessments to help defend systems against threats. Strong practical knowledge of web and network pentesting methodologies and tools is required.
Key Responsibilities
- Static and Dynamic Application Security Testing (SAST & DAST)
- Vulnerability Assessment and Penetration Testing
- Red Teaming and Offensive Security Assessment
- GRC and Auditing
- Research and Knowledge Development
Vulnerability Assessment and Penetration Testing
- Conduct in-depth vulnerability assessments and penetration tests across various platforms, including web applications, APIs, network infrastructures, and mobile applications.
- Identify potential vulnerabilities, simulate real‑world attack scenarios, and provide detailed remediation recommendations to mitigate risks effectively.
Red Teaming and Related Activities
- Plan, execute, and document comprehensive Red Team engagements to assess the security posture of organizations.
Offensive Security Assessment of Specialized Environments
- Perform offensive security assessments of Operational Technology (OT) environments, Industrial Control Systems (ICS), and cloud‑based infrastructures.
Compliance and Regulatory Audits
- Assist in preparing for and conducting compliance audits to meet industry standards and regulations (e.g., GDPR, ISO 27001, SOC Type 1‑2, PCI DSS).
Static and Dynamic Application Security Testing (SAST & DAST)
- Conduct thorough SAST and DAST analyses to identify vulnerabilities in application code.
- Review and provide secure coding guidelines to developers for mitigating risks at the code level.
Black Box Penetration Testing
- Conduct and teach Black Box penetration testing methodologies, simulating an attacker's perspective with no prior knowledge of the target system.
- Develop hands‑on training modules for students and team‑mates to enhance their penetration testing skills.
Research and Knowledge Development
- Continuously explore and analyze new attack strategies, tools, and techniques to stay updated with the evolving cybersecurity landscape.
Skills and Qualifications
Educational Background
BE, BTech, BCA, BSC or equivalent academic provision
Soft Skills
- Excellent communication and presentation skills, with the ability to explain complex security topics in a clear and engaging manner.
- Strong problem‑solving abilities and analytical thinking.
- Ability to work independently as well as part of a team.
- Strong time management and organizational skills.