Security Analyst – Vulnerability Assessment and Penetration Testing
Al Rayyan, Qatar · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 4 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
We seek an experienced Security Analyst specialized in conducting thorough Vulnerability Assessment and Penetration Testing (VAPT) within complex IT ecosystems. This role involves testing enterprise environments including networks, applications, infrastructure, cloud platforms, and security frameworks to identify and mitigate vulnerabilities effectively.
Key Duties
- Execute both internal and external penetration tests encompassing networks, servers, firewalls, endpoints, and related infrastructure components.
- Conduct detailed security testing of web applications and APIs, focusing on OWASP vulnerability assessment.
- Perform vulnerability scans followed by manual verification to identify false positives and validate findings.
- Carry out controlled exploitations to assess impact and risk severity of detected security weaknesses.
- Test security configurations and vulnerabilities across network devices such as firewalls, routers, switches, VPNs, load balancers, and servers.
- Assess application security aspects including authentication, authorization, session management, input sanitation, encryption, and business logic flaws.
- Review source code security and provide support for Static and Dynamic Application Security Testing activities.
- Evaluate security postures of cloud infrastructures and operating systems.
- Utilize security tools such as Burp Suite, Nmap, Nessus, Metasploit, Wireshark, and Kali Linux for comprehensive assessments.
- Develop security automation scripts or tools with Python to streamline penetration testing processes.
- Prepare detailed reports documenting vulnerabilities, evidences, risk levels, business impacts, and recommended mitigations.
- Collaborate with technical teams to resolve identified vulnerabilities and conduct follow-up retesting to confirm remediation.
- Adhere to established penetration testing methodologies and cybersecurity best practices.
- Support organizational security teams by identifying potential attack vectors and enhancing overall security defense mechanisms.
Technical Expertise
- Proficient in Vulnerability Assessment and Penetration Testing methodologies.
- Hands-on experience in network, web application, API, infrastructural and cloud security testing.
- Skilled in exploitation and validation of vulnerabilities and familiar with the OWASP Top 10 security risks.
- Experienced in Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and source code analysis.
- Knowledgeable in secure coding best practices and operating system/network security.
- Advanced use of tools including Burp Suite, Nmap, Nessus, Metasploit, Wireshark, and Kali Linux.
- Ability to automate security testing processes using Python scripting.
Standards and Frameworks
- Strong understanding of cybersecurity and compliance standards such as OWASP, NIST, ISO/IEC 27001, and PCI DSS.
- Familiarity with penetration testing methodologies and industry best practices.
Skills
Tools & software
Nmap
required
Metasploit
required