Key Responsibilities:
1. Offensive Security Delivery (Execution)
Aligns with Manager’s responsibility for Offensive Security
- VAPT Execution: Perform comprehensive Network, Web Application, and Mobile Application penetration testing. You will go beyond automated scanners to identify critical logic flaws and business risks.
- Phishing Simulations: Design and execute \"Phishing Simulation\" campaigns, crafting realistic scenarios to test client human defenses.
- Technical Depth: Ensure all technical activities maintain \"adherence to global standards\" (e.g., OWASP, PTES) and meet the quality requirements set by the Consulting Manager.
2. Reporting & Commercial Awareness
Aligns with Manager’s responsibility for Account Mining & Reviews
- Strategic Reporting: Author detailed technical reports that do not just list bugs, but \"spot business risks in technical findings\". Your reports must be written in a way that allows the Manager to \"review deliverables with customers... to identify gaps that lead to new opportunities\".
- Root Cause Analysis: Instead of just reporting a vulnerability, analyze the systemic failure (e.g., poor coding practices) to help the Manager propose broader \"Advisory services\" or \"Training Academy\" solutions.
3. AI Integration & Process Modernization
Aligns with Manager’s responsibility for Innovation & AI Integration
- AI-Assisted Workflow: Actively utilize the AI/LLM tools implemented by the Manager to \"optimize reporting and data analysis\".
- Automation: Contribute to \"Methodology Enhancement\" by scripting routine scanning tasks or \"automating report generation\" to reduce non-billable hours and improve efficiency.
- Dynamic Scenarios: Assist in generating \"dynamic phishing scenarios\" using AI tools to keep testing methodologies ahead of the curve.
4. Mentorship & Utilization
Aligns with Manager’s responsibility for Resource Management & Team Motivation
- Tier 1 Mentorship: Act as a technical mentor for Junior (Tier 1) Analysts, reviewing their code and reports to ensure quality control before deliverables reach the Manager.
- Billable Efficiency: Maintain a high personal \"Billable Utilization\" rate by executing projects efficiently and minimizing idle time.
Qualifications:
- 3-5 years of hands-on experience in Information Security Consulting, specifically focused on VAPT or Red Teaming (Aligns with Manager's requirement for 8+ years, scaled for Tier 2).
- Proven experience writing technical reports for external clients.
Technical Competencies:
- Offensive Mastery: Deep proficiency in Burp Suite, Metasploit, Nmap, and Cobalt Strike. Strong understanding of \"Offensive Security (Red Teaming)\" methodologies.
- Frameworks: Working knowledge of OWASP (Top 10/API), NIST, and GDPR as they relate to vulnerability management.
- AI Adaptability: \"Understanding of how to leverage AI tools\" (e.g., ChatGPT, Copilot for Security) to assist in code review or payload generation.
Certifications:
- Must possess or be actively pursuing OSCP (Offensive Security Certified Professional).
- Other relevant certifications: CEH, GPEN, or GWAPT.
Success Metrics (KPIs)
- Billable Utilization: Maintaining a target utilization rate (e.g., 75%+) on assigned projects.
- Time-to-Report: Successfully using AI tools to reduce the time spent on report writing, contributing to the Manager's \"Delivery Innovation\" target.
- Deliverable Quality: Low rejection rate of reports during the Manager’s review, supporting high \"Customer Satisfaction\" and NPS scores.
- Upsell Identification: Number of projects where technical findings successfully highlighted a gap that resulted in a \"follow‑on work\".
Data Privacy Notice
Novare values your privacy. By submitting your application, you hereby authorize Novare and its Affiliates to collect and process your Personal Information and Sensitive Personal Information (as defined under R.A. No. 10173 or the Data Privacy Act) contained in your resume and other documents and information provided to the Company for the processing of your job application. Your data is stored in Novare’s secure databases and retained until the expiration of the retention limit provided by law or when you revoke your consent.