Cybersecurity Vulnerability Analyst

ARHS

Warszawa

On-site

PLN 180,000 - 260,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ARHS Group, part of Accenture, seeks a Cybersecurity Vulnerability Analyst in Warsaw to manage vulnerability assessments, conduct tests, and ensure compliant, secure IT systems. The role emphasizes proactive vulnerability management, secure coding awareness, and collaboration with global teams.

Applicants should hold an EU security clearance, English at CEFR B2, and a strong background in OSS/SDLC, network security, and threat remediation.

Qualifications

  • Bachelor's degree plus 8 years of IT relevant professional experience
  • Minimum 5 years of experience at similar position
  • Active EU Security Clearance is required
  • Minimum English language skills (CEFR) : B2
  • Knowledge of systems development life cycle
  • Knowledge of operating systems security
  • Knowledge of computer networks security
  • Knowledge of security controls
  • Knowledge of offensive and defensive security practices
  • Knowledge of secure coding practices
  • Possesses hands-on experience in ICT in the role of Cybersecurity Vulnerability Analyst
  • Knowledge of system security vulnerabilities, threats and exploit mechanisms, penetration testing, remediation techniques and risk analysis methodologies
  • Knowledge of OWASP family standards
  • Practical knowledge of designing and performing security tests
  • Practical knowledge of Tenable vulnerability management suite, NMAP, Wireshark, BurpSuite
  • Analytical mind, attention to details and an ability to pick things up quickly; problem solving skills
  • Document, report, present and communicate with various stakeholders
  • Develop codes, scripts and programmes
  • Identify and exploit vulnerabilities
  • Think creatively and outside the box
  • Identify and solve cybersecurity-related issues
  • Communicate, present and report to relevant stakeholders
  • Use penetration testing tools effectively
  • Conduct technical analysis and reporting
  • Decompose and analyse systems to identify weaknesses and ineffective controls
  • Review codes, assess their security, integrate cybersecurity solutions to the organisation's infrastructure
  • Configure solutions according to the organisation's security policy
  • Assess the security and performance of solutions
  • Develop and test secure code and/or scripts
  • Identify and troubleshoot cybersecurity-related issues

Responsibilities

  • Receiving information and reports about hardware and software vulnerabilities; analysing the nature, mechanics, and effects of the vulnerabilities; and developing response strategies for detecting and repairing the vulnerabilities.
  • Proactively managing vulnerabilities by performing vulnerability assessments, penetration tests and reviewing the technical security compliance of systems and services.
  • Managing response to disclosed vulnerabilities for which no countermeasure is yet available.
  • This service can involve communicating with vendors, other CSIRTs, technical experts, consultant members, and the individuals or groups who initially discovered or reported the vulnerability.
  • Evaluates results of security audits and tests, security findings, priorities, plans, and implements remediation controls.
  • Provides forensic analysis in response to information security incidents.
  • Assesses security controls of new applications to establish compliance level and appropriate configuration.
  • Performing vulnerability watch.
  • Processing of incoming vulnerability warnings, alerts and reports.
  • Oversee the management of known vulnerabilities through established processes and procedures.
  • Triage based on verification, level of exposure and impact assessment.
  • Analysing and examining vulnerabilities in hardware or software.
  • Validating the existence of suspected vulnerabilities by determining where they are located and how they can be exploited.
  • Reviewing source code, using a debugger to determine where the vulnerability occurs, or trying to reproduce the problem on a test system.
  • Notifying the various parts of the Agency about the vulnerability and shares information about how to fix or mitigate the vulnerability.
  • Verifying that the vulnerability response strategy has been successfully implemented.
  • Performing regular vulnerability scans of system and applications, writing reports including recommendations for improvements and following-up the remediation process for identified vulnerabilities.
  • Providing regular reports and dashboards (based on KPIs) to monitor security improvements.
  • Performing penetration tests and writing reports including recommendations for improvements.
  • Reviewing the technical security compliance of systems against defined security baselines (gold configuration), writing reports and following-up the remediation process for identified non-compliance.
  • Participating in the definition of security baselines.
  • Provide activity reports to management to demonstrate service SLA and service quality.

Skills

Vulnerability analysis
Penetration testing
Security auditing
OWASP
Nmap
Wireshark
BurpSuite
Secure coding
English B2

Education

Bachelor's degree

Tools

Tenable
Nmap
Wireshark
BurpSuite
WAF
EDR

Job description

Arηs Group, Part of Accenture, specializes in the management of complex public sector IT projects, including systems integration, informatics and analytics, solution implementation and program management. Our team helps lead clients through digital and information systems design, bringing expertise in a variety of areas ranging from software development, data science and security management to machine learning, cloud, and mobile development.Arηs Group was acquired by Accenture in July 2024.

Job Description
  • Receiving information and reports about hardware and software vulnerabilities; analysing the nature, mechanics, and effects of the vulnerabilities; and developing response strategies for detecting and repairing the vulnerabilities.
  • Proactively managing vulnerabilities by performing vulnerability assessments, penetration tests and reviewing the technical security compliance (deviation from a baseline configuration) of systems and services.
  • Managing response to disclosed vulnerabilities for which no countermeasure is yet available.
  • This service can involve communicating with vendors, other CSIRTs, technical experts, consultant members, and the individuals or groups who initially discovered or reported the vulnerability.
  • Evaluates results of security audits and tests, security findings, priorities, plans, and implements remediation controls.
  • Provides forensic analysis in response to information security incidents.
  • Assesses security controls of new applications to establish compliance level and appropriate configuration.
  • Performing vulnerability watch.
  • Processing of incoming vulnerability warnings, alerts and reports.
  • Oversee the management of known vulnerabilities through established processes and procedures.
  • Triage based on verification, level of exposure and impact assessment.
  • Analysing and examining vulnerabilities in hardware or software.
  • Validating the existence of suspected vulnerabilities by determining where they are located and how they can be exploited.
  • Reviewing source code, using a debugger to determine where the vulnerability occurs, or trying to reproduce the problem on a test system.
  • Notifying the various parts of the Agency about the vulnerability and shares information about how to fix or mitigate the vulnerability.
  • Verifying that the vulnerability response strategy has been successfully implemented.
  • Performing regular vulnerability scans of system and applications, writing reports including recommendations for improvements and following-up the remediation process for identified vulnerabilities.
  • Providing regular reports and dashboards (based on KPIs) to monitor security improvements.
  • Performing penetration tests and writing reports including recommendations for improvements.
  • Reviewing the technical security compliance of systems against defined security baselines (gold configuration), writing reports and following-up the remediation process for identified non-compliance.
  • Participating in the definition of security baselines.
  • Provide activity reports to management to demonstrate service SLA and service quality.
Qualifications
  • Bachelor's degree plus 8years of IT relevant professional experience
  • Minimum 5 years of experience at similar position
  • Active EU Security Clearance is required
  • Minimum English language skills (CEFR) : B2
  • Knowledge of systems development life cycle
  • Knowledge of operating systems security
  • Knowledge of computer networks security
  • Knowledge of security controls
  • Knowledge of offensive and defensive security practices
  • Knowledge of secure coding practices
  • Possesses hands-on experience in ICT in the role of Cybersecurity Vulnerability Analyst
  • Knowledge of system security vulnerabilities, threats and exploit mechanisms, penetration testing, remediation techniques and risk analysis methodologies
  • Knowledge of OWASP family standards
  • Practical knowledge of designing and performing security tests
  • Practical knowledge of Tenable vulnerability management suite, NMAP, Wireshark, BurpSuite
  • Analytical mind, attention to details and an ability to pick things up quickly; problem solving skills
  • Document, report, present and communicate with various stakeholders
  • Develop codes, scripts and programmes
  • Identify and exploit vulnerabilities
  • Think creatively and outside the box
  • Identify and solve cybersecurity-related issues
  • Communicate, present and report to relevant stakeholders
  • Use penetration testing tools effectively
  • Conduct technical analysis and reporting
  • Decompose and analyse systems to identify weaknesses and ineffective controls
  • Review codes, assess their security, integrate cybersecurity solutions to the organisation's infrastructure
  • Configure solutions according to the organisation's security policy
  • Assess the security and performance of solutions
  • Develop and test secure code and/or scripts
  • Identify and troubleshoot cybersecurity-related issues

Specific requirements:

  • Experience in vulnerabilities analysis
  • Knowledge of risk assessment in the context of given vulnerability and its environment
  • Experience in coordination and execution of PenTests
  • Experience in implementing protections against the most common types of exploits for web apps
  • Proficient in writing reports covering vulnerabilities and patch management
  • Experience in reviewing current security controls and proposing improvements
  • Experience in writing security procedures/policies with emphasis in information protection and data privacy
  • Experience in administering security solutions – Vulnerability platform, WAF, EDR
  • Innovative approach to new technologies

Required certificates(At least 3 certifications among):

  • GCWN (GIAC Certified Windows Security Administrator)
  • GCUX (GIAC Certified UNIX Security Administrator)
  • GCCC (GIAC Certified Critical Controls)
  • SSCP (ISC² Certified Systems Security Practitioner)
  • GCWN (GIAC Certified Windows Security Administrator)
  • GCUX (GIAC Certified UNIX Security Administrator)
  • GCCC (GIAC Certified Critical Controls)
  • GXPN (GIAC Certified Exploit Researcher and Advanced Penetration Tester)
  • GMOB (GIAC Certified Mobile Device Security Analyst)
  • NDS (EC-Council Certified Security and Vulnerability Assessor)
  • ECSA (EC-Council Certified Security Analyst)
  • GSNA (GIAC Certified Systems and Network Auditor)
  • GSEC (GIAC Certified Security Essentials)
  • ECSA (EC-Council Certified Security Analyst)
  • SCPO (SABSA Certified Security Operations & Service Management Practitioner)
  • ECSA (EC-Council Certified Security Analyst)
  • or for any listed above, an equivalent alternative certification recognized internationally (subject to acceptance as a valid credential by the Contracting Authority).

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CyberSecurity Risk Manager
CyberSecurity Risk Manager

Arhs Group • Warszawa

On-site
PLN 420,000 - 640,000
Cybersecurity Project Manager
Cybersecurity Project Manager

ARHS • Warszawa

On-site
PLN 240,000 - 380,000
Solutions Architect
Solutions Architect

ARHS • Warszawa

On-site
PLN 180,000 - 260,000
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex at The Whiteam
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex at The Whiteam

The Whiteam • Warszawa

Hybrid
PLN 180,000 - 240,000
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex
CyberSecurity L&M Service Specialist (Warsaw, 80% remote) – Frontex

TheWhiteam • Warszawa

Hybrid
PLN 180,000 - 240,000
Cybersecurity Risk Manager (EU Security Environment)
Cybersecurity Risk Manager (EU Security Environment)

Aricoma • Warszawa

On-site
PLN 180,000 - 320,000
Security Penetration Tester
Security Penetration Tester

DataLock Consulting Group • Poland

Remote
PLN 252,000 - 380,000
Vulnerability Management Analyst & Automation specialist
Vulnerability Management Analyst & Automation specialist

Euroclear • Województwo małopolskie

Hybrid
PLN 60,000 - 80,000
Cybersecurity Network Security Specialist
Cybersecurity Network Security Specialist

Vector Synergy • Warszawa

Hybrid
PLN 212,000 - 298,000
Cybersecurity Architect
Cybersecurity Architect

Vector Synergy • Warszawa

On-site
PLN 100,000 - 130,000