Analyst - Attack Surface Management (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Analyst - Attack Surface Management (Cybersecurity): Leading attack surface reconnaissance and asset identification to protect external assets with an accent on vulnerability management and risk assessment. Focus on applying penetration testing techniques, automating monitoring using cloud-based solutions, and mentoring junior analysts.
Location: Krakow, Poland (Must be authorized to work in Poland, no visa sponsorship provided)
Company
is a world leader in gaming content and technology, specializing in the delivery of B2B casino and mobile games.
What you will do
- Lead attack surface reconnaissance efforts and asset identification.
- Manage parts of the vulnerability management program, including onboarding new assets.
- Conduct in-depth security vulnerability analysis and provide sophisticated risk assessments.
- Apply penetration testing techniques to validate and exploit security gaps.
- Implement automation for attack surface monitoring using scripting and cloud-based solutions (Azure, GCP).
- Mentor junior analysts and communicate risks and mitigation strategies to executive leadership.
Requirements
- 4+ years of experience in cybersecurity concentrating on security operations or offensive security.
- Advanced knowledge of vulnerability management, OSINT, and adversary simulation.
- Strong expertise with tools including Kali Linux, Burp Suite, Tenable, and Splunk.
- Experience in cloud security assessment (Azure and GCP) and familiarity with AI models.
- Understanding of regulatory frameworks such as ISO27001.
- Must be authorized to work in Poland without the need for current or future visa sponsorship.
Culture & Benefits
- Opportunity to work with a world leader in gaming entertainment.
- Robust benefits package.
- Access to global career opportunities.
- Inclusive work environment that values diversity and employee wellbeing.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →