Company

Claranet LimitedSee more

addressAddressUnited Kingdom
type Form of workPermanent
salary SalaryCompetitive
CategoryHuman Resources

Job description

About The Role

The Continuous Security Testing service is a consultant led vulnerability identification and verification service which makes use of automated vulnerability scanning along with significant manual testing against a broad scope in a continuing engagement. The purpose of the service is to continually monitor a customer's external attack surface for new vulnerabilities, changes in the scope of the attack surface, and proactively inform customers of discovered issues along with recommended remediation; with the overall aim of reducing the lifetime of each vulnerability. Manual testing includes identification of issues which automation alone could not identify, exploitation of all issues, often chaining multiple findings together in order to determine the true impact of vulnerabilities for the customer.

  • Pre–engagement activities including scoping of assessments and statements of work and determining customer requirements and restrictions.
  • On boarding customers into the service including configuration of continual scanning and liaising with customer to resolve issues which may reduce the effectiveness of scanning.
  • Monitoring of the customers' external perimeter for changes, and proactive discovery of new targets to include within the customer's scope.
  • Manual identification and exploitation of vulnerabilities.
  • Manual verification and exploitation of scanner findings.
  • Detailed analysis of issues identified and exposure for the customer including proof of concept, reproduction steps, and recommended remediation.
  • Communication of findings to the customer in a detailed, accurate and manageable manner both orally and through written vulnerability/scope notifications and periodic summaries.
  • Assisting in the continual development of the team and service through research and development activities. This includes the development of in–house tools the implementation of tools released to the community, and design and documentation of new and existing internal systems and processes.
  • Continual professional development to maintain and develop knowledge and technical competencies.
  • Maintain professional technical qualifications to demonstrate competency to our clients.
  • Contributing to the writing and publishing of whitepapers and advisories.
  • Undertaking projects and support tasks as appropriate to the role.

About You

Essential

Technical:

  • Core computing skills including but not limited to:
    • Networking fundamentals – understanding of OSI Model, TCP/IP, HTTP, DNS, SMB, SMTP and relevant tools.
    • Microsoft Windows and Office proficiency along with proficiency in one or more Linux distributions.
  • Strong knowledge of web application technologies and security assessment including but not limited to:
    • REST APIs, SOAP APIs, XML and JSON formats.
    • Vulnerability identification and exploitation (not limited to OWASP Top 10).
    • Experience with common assessment tools such as MITM proxies (e.g. Burp Suite Pro) and SQLMap.
  • Good knowledge of internal and external infrastructure technologies and security assessment including but not limited to:
    • Identification and exploitation of misconfigurations or known vulnerabilities in common enterprise infrastructure and services (Windows Domains, Linux servers, virtualisation, databases, switches/routers, etc).
  • Knowledge of a scripting language such as Python (preferred), Ruby, PowerShell, or Bash, for the development of new, or editing existing, tools.

Essential Experience:

  • Providing remediation advice
  • Producing accurate technical reports
  • Working under pressure of deadlines and structuring workload accordingly
  • Problem–solving, helping others to understand complex ideas

Essential General:

  • Client facing, able to confidently and professionally represent the company
  • Must be self–motivated and able to work in an independent manner as well as part of a team
  • Excellent written and oral communications skills
  • Positive, collaborative and enthusiastic
  • Appetite to shadow, train and develop to improve capabilities into all areas of security testing

In addition, the following are highly desirable:

  • CPSA, CRT, OSCP or equivalent reputable information security certifications
  • Familiarity with testing cloud environments
  • Public speaking experience
Refer code: 3417542. Claranet Limited - The previous day - 2024-06-21 17:40

Claranet Limited

United Kingdom

Share jobs with friends

Related jobs

Penetration Tester (Cst)

Infrastructure Penetration Tester

Major Players

Up to £0.00 per annum

Brussels

3 days ago - seen

CHECK Team Lead Penetration Tester

Profectus Recruitment

Berkshire, England

3 days ago - seen

Senior Penetration Tester

Stott And May

70000-80000

London, England

3 days ago - seen

Penetration Tester

Stott And May

50000-60000

London, England

3 days ago - seen

Penetration Tester, EMEIA IS&T

Apple

London, Greater London

6 days ago - seen

Penetration Tester

Royal London Group

Edinburgh, City of Edinburgh

6 days ago - seen

Penetration Tester with Security Clearance

Graham Technologies

Competitive

United States

6 days ago - seen

Penetration Tester with Security Clearance

Ecs

140000.00 - 155000.00 USD Annual

United States

6 days ago - seen

Penetration Tester Lead with Security Clearance

Graham Technologies

Competitive

United States

6 days ago - seen

BDO Digital Senior Penetration Tester

Bdo

Competitive + benefits

London, Greater London

6 days ago - seen

Penetration Tester

Barclay Simpson

Competitive

Remote

6 days ago - seen

Senior Penetration Tester

Matchtech

£60,000 - £80,000/annum

Solihull, West Midlands

4 weeks ago - seen

Penetration Tester/RedSeal SME with Security Clearance

Data Intelligence Llc.

Competitive

United States

4 weeks ago - seen

Penetration Tester

Heat Recruitment

40000.00 - 80000.00 GBP Annual

London, England

4 weeks ago - seen

Penetration Tester

Heat Recruitment

South East

a month ago - seen

Penetration Tester

Reperio Human Capital

£345 - £388/day

Athlone, Westmeath

a month ago - seen

Penetration Tester (CST)

Claranet

Competitive

Remote

a month ago - seen

Senior Penetration Tester - CTL - £70,000 - £80,000

Lawrence Harvey

£70,000 - £80,000 per annum

South East

2 months ago - seen