Attack Surface Management Engineer

Detalles de la oferta

**Job Title**:
Attack Surface Management Engineer

**Job Category**:
Professional

**Department/Group**:
Attack Surface Management

**Position Type**:
Full time

**Location**:
Remote, Costa Rica

**Reports to**:
Director Attack Surface Management
- Attack Surface Management EngineerDescription

The Attack Surface Management Engineer is responsible for activities related to Attack Surface Management, with the goal to ensure comprehensive visibility and actionability of the companies external attack surface, exposures, and vulnerabilities, minimizing the companies risk potential.

Functions
- Follows Attack Surface Mgmt processes to continuously monitor and improve visibility of the attack surface in order to detect anomalies faster and reduce incidences or potential of cyber-attacks.
- Generate comprehensive reports, including detailed findings, exploitation procedures, and mitigation techniques.
- Engage with business stakeholders to ensure they fully understand their Attack Surface, and helps them identify prioritization of vulnerabilities.
- Develops vulnerability KPIs/metrics to demonstrate coverage and remediation effectiveness.
- Execute daily operations of the Attack Surface Mgmt program, including the interpretation of scanning results.
- Asist in the identification of internal and external risks based on scanning results.
- Assist in the attribution of findings to appropriate business owner.
- Identify improvements to scan coverage.
- Coordinate with IT and geographically dispersed Business Units on vulnerability remediation and mitigation strategies.
- Assist in the documentation and standardization of process and procedures related to Attack Surface Mgmt
- Aggregating vulnerability data across technologies such as endpoints, servers, network equipment, and cloud and interpreting and presenting risk.

Responsibilities/Requirements
- Familiarity with common web vulnerabilities including: XSS, XXE, SQL Injection, Deserialization Attacks, Path Traversal Attacks, Remote Execution Flaws, and Authentication Flaws.
- Experience with one or more scripting languages such as Bash, Python, Perl, PowerShell, etc.
- Working knowledge of networking standards and protocols: IPv4 IPv6, TCP/IP, DNS, HTTPS, TLS, BGP, Firewalls and NAT, SMTP, VPN, ICMP, SSH, IPSec, etc.
- In-depth knowledge of architecture, engineering, and operations of one or more vulnerability management tools, such as Wiz, Qualys, Rapid7 and ServiceNow.
- Ability to provide creative solutions to complex problems.
- Ability to clearly communicate risk of vulnerabilities to all levels within an organization.
- Knowledge of major cloud platforms (AWS, Azure, or GCP).
- Knowledge of systems hardening and other risk mitigation factors on multiple technologies and operating systems (Window, Linux, Mac, routers, switches, Kubernetes).
- Ability to manage, organize, analyze, and present substantial amounts of data.
- Experience selecting and deploying product.

Position Requirements

Formal Education & Certification
- Four-year college diploma or university degree in computer science or computer engineering, and/or 3 years equivalent work experience.

Knowledge & Experience
- Certification that could be helpful but not required: CISSP, Security+, CEH, GIAC certifications.
- 2-4+ years of experience in information security vulnerability management role. 6+ years in security and/or technology engineering roles.
- Experience with large scale and complex environments.
- A broad and deep understanding of cybersecurity threats, vulnerabilities, controls, and remediation strategies.
- Applied knowledge and experience in cybersecurity, technology infrastructure, vulnerability management and security and controls.
- Excellent interpersonal skills and strong verbal and written communication.
- An ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily-understood and actionable manner.
- Strong organizational skills with proven ability to manage multiple high visibility issues simultaneously.
- Proactive attitude, seeking for improvement opportunities which can positively impact the security posture and the business.

Personal Attributes
- Excellent oral and interpersonal communication skills.
- Outstanding writing and documentation skills.
- Able to communicate ideas in both technical and user-friendly language.
- Highly self-motivated and directed, with keen attention to detail.
- Able to prioritize and execute tasks in a high-pressure environment.
- Experience working in a team-oriented, collaborative environment.
- Willing to travel globally as required.


Salario Nominal: A convenir

Fuente: Whatjobs_Ppc

Requisitos

Ingeniero (A) De Proceso

**Ingeniero (a) de Proceso**: - Experience Level: Recent College Grad- Job Type: Full-Time- Location: Costa Rica - Heredia, CR- Requisition ID: 7569**Nature...


Qorvo - Heredia

Publicado a month ago

Técnico De Calibraciones Iii

TE Connectivity's Technical Engineering Support Teams analyze, test and assist in research for the development of products and processes. Team members may sp...


Te Connectivity - Heredia

Publicado a month ago

Hardware Engineer

3 years of experience as a data center engineer, or similar as an Engineering Technician able to disassembly and reassembly of Personal Computers/Servers. - ...


Infotree Global Solutions - Heredia

Publicado a month ago

Mechanical Design Engineer / Ingeniero De Diseño

**PLEASE NOTE WE ARE AN INTERNATIONAL COMPANY. PLEASE SUBMIT YOUR APPLICATION IN ENGLISH.** **TENGA EN CUENTA QUE SOMOS UNA EMPRESA INTERNACIONAL. ENVÍE SU ...


Triz Engineering Services - Heredia

Publicado a month ago

Built at: 2024-11-21T17:17:35.234Z