10 дней назад
Senior Vulnerability Analyst (CTEM)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Vulnerability Analyst (CTEM): Managing continuous threat exposure across cloud environments, identities, endpoints, applications, infrastructure, and external attack surfaces with an accent on vulnerability validation, risk-based prioritization, and remediation coordination. Focus on analyzing attack paths and threat intelligence, developing exposure dashboards and metrics, and supporting purple team exercises and control validation.
Location: Cairo, Egypt; hybrid work with work-from-home up to 2 days per week depending on team needs
Company
provides technology and communications solutions for airports, airlines, borders, and the global air travel industry.
What you will do
- Maintain enterprise exposure visibility across cloud environments, identities, endpoints, applications, infrastructure, and external attack surfaces.
- Perform vulnerability assessments and analyze vulnerabilities, misconfigurations, attack paths, asset criticality, and threat intelligence.
- Prioritize and validate exposures based on business risk, exploitability, threat intelligence, and asset criticality.
- Coordinate remediation with infrastructure, cloud, application, and technology teams, tracking exceptions, compensating controls, and risk acceptance.
- Develop CTEM dashboards, executive summaries, operational metrics, and leadership reports.
- Support purple team exercises, tabletop activities, security assessments, and control validation initiatives.
Requirements
- 3–5 years of experience in vulnerability management, exposure management, cloud security, security operations, or risk management.
- Experience managing the end-to-end vulnerability and exposure lifecycle, including discovery, prioritization, remediation, validation, exceptions, and closure.
- Knowledge of vulnerability scanners, cloud security posture management, attack surface management, and CMDB or asset inventory solutions.
- Understanding of CVSS, EPSS, CISA KEV, exploitability analysis, asset criticality, attack-path analysis, SOC monitoring, and MITRE ATT&CK.
- Proficiency with Excel, Power BI, KQL, SQL, Python, or similar data analysis and reporting tools.
- Bachelor’s degree in IT, cybersecurity, computer science, or a related field, or equivalent experience; at least one recognized cybersecurity certification is required.
Nice to have
- Experience supporting CTEM initiatives in large enterprise environments.
- Familiarity with Microsoft Azure, Microsoft 365, AWS, or hybrid cloud security tools.
- Experience with purple team exercises, threat-informed defense, attack simulation, or control validation programs.
Culture & Benefits
- Hybrid flexibility with up to 2 work-from-home days per week, depending on team needs.
- Flex Day scheduling and up to 30 days per year working from any location in the world.
- Employee Assistance Program and wellbeing support through Champion Health.
- Professional development through LinkedIn Learning, Microsoft’s Enterprise Skills Initiative, Pluralsight, and other learning platforms.
- Competitive benefits aligned with local market and employment status.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →