Summary
Join Netskope's Threat and Vulnerability Management team as an Analyst to proactively mitigate security risks and vulnerabilities. You will identify and reduce vulnerable attack surfaces, analyze emerging threats, and develop mitigations. Responsibilities include vulnerability management, reporting, and supporting business units in remediation efforts. You will also automate security tasks using scripting languages, maintain threat models, and partner with internal teams to develop and validate detection signatures. The role requires expertise in incident response and a strong understanding of vulnerability ratings and methodologies. This position offers the opportunity to contribute to a dynamic and collaborative team.
Requirements
- Experience 2 to 5 Yrs in Security
- Should possess relevant university degree and/or professional qualifications/certification (e.g. CEH, OSCP)
- Must have knowledge with tools Tenable, Qualys, NMAP, SCAPY, and other tools
- Must have the ability to understand hardening guidelines for new technologies and applications being adopted by Netskope
- Understanding of containerization and containerized applications, their security weaknesses and how to secure them
- Must have an understanding of patch automation, security orchestration, and management tooling for on premise, private cloud, and cloud infrastructure
- Knowledge of OWASP Web and Mobile Top 10 vulnerabilities and identifying them
- Knowledge of TCP/IP and other application and network level protocols
- Knowledge of Cloud Applications like AWS, Azure and other SAAS Applications
- Excellent written and verbal communication skills
- Self-motivated, curious, knowledgeable pertaining to news and current events
- Ability to be effective in a remote global work environment
Responsibilities
- Continuous development and execution of the enterprise Threat and Vulnerability Management strategic plan to identify and reduce vulnerable attack surfaces
- Perform complex analysis to understand emerging threats, and continuously demonstrates awareness of current threat posture
- Reviews emerging and existing threat methodologies and exploit code / proof of concept code to develop mitigations, prioritize risks and navigating sources for identification of vulnerable assets
- Execute on core team functions such as scanning, reporting, custom checks, asset tagging, as well as incorporating threat intelligence into vulnerability checks
- Automate security tasks using scripting languages such as python
- Maintain and contribute to the threat models understanding emerging/existing threats and countermeasures to them
- Partners with internal teams to lead, develop, test, and continuously validate detection signatures for various attacks
- Provide internal teams with hardening guidance and develop tooling for auditing
- Support teams by being a Remediation Champion giving them guidance on various strategies to remediate a vulnerability and supporting them in their testing and validation efforts
- Provides expertise in incident response activities
- Teach and understand CVSS, CVE, and additional vulnerability ratings and methodologies
Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.