Vulnerability Analyst
1 week ago
Overview Vulnerability Analysts aid in the identification, assessment, and communication of new and emergent threats in the cybersecurity landscape, specifically vulnerability intelligence and detections. As a Vulnerability Analyst, you will be expected to familiarize yourself with high-impact and critical vulnerabilities, proofs-of-concept, and reports of in-the-wild exploitation, producing and reviewing intelligence summaries accessible to Client's customers. Specific Duties and Responsibilities Vulnerability Lead Identification and Analysis: You will be tasked with the prompt identification, analysis, and comprehensive assessment of emerging cybersecurity threats, specifically recently disclosed or exploited vulnerabilities. Subject Matter: Your technical prowess will be crucial in ensuring our preparedness for potential risks and understanding the implications of prompt and thorough analysis of high-impact vulnerabilities. Key Detail Identification: During research, identify and take note of infection chains, host and network IoCs, malware samples, threat actors, exposed vulnerable instances, publicly available proofs-of-concept, and MITRE ATT&CK tactics and techniques Author Insikt Notes: Write TTP Instances detailing identified vulnerability leads. TTP Instances include a combination of information from open-source reporting and your own analysis (i.e. code review). Each TTP Instance should comprehensively address the nature of the threat, its potential impact, suggested mitigation strategies, and a succinct summary for quick referencing. Cadence and Quality: Write at least 2 TTP Instance notes daily with minimal grammatical or syntax errors. Plagiarism is not acceptable. Detection Engineering: Design and develop Nuclei templates for vulnerability scanning, ensuring these templates are tailored to detect new and emerging vulnerabilities efficiently. Cadence: Create at least 1 Nuclei template per month with assistance from our Senior Vulnerability Analyst. Delivery: Nuclei templates will be delivered alongside a TTP Instance. Information Security: Adhere to and implement quality and information security policies and carry out its processes and procedures accordingly. Protect client-supplied and generated-for-client information from unauthorized access, disclosure, modification, destruction, or interference. Carry out tasks as assigned and aligned with particular processes or activities related to information security. Report any potential or committed non-conformity, observation and/or security event or risks to your immediate superior. Qualification Required Skills Strong written communication in English Demonstrable experience writing reports on technical subject matter (e.g. vulnerability exploits, malware infection chains, offensive security tools) in a clear, concise, and logical format Disciplined time management Self-starting, self-motivated, and thrive in a collaborative environment Ability to receive and apply constructive feedback from peers and leadership Minimum Qualifications B.S. equivalent in computer science, information systems, or cyber intelligence 1 - 2 years of minimum professional experience in cybersecurity, with a focus on threat detection, penetration testing, or vulnerability assessment. A solid grasp of fundamental cybersecurity principles, attack trajectories, and techniques for vulnerability analysis. Demonstrable experience researching and analyzing new cyber threats. Practical experience using common threat intelligence analysis models such as MITRE ATT&CK, D3FEND, the Diamond Model, and the Cyber Kill Chain. Familiarity with and use of common cyber threat intelligence tools such as DomainTools, VirusTotal, Shodan, etc. Demonstrable experience in technical writing, showcasing an ability to translate complex technical concepts into engaging, reader-friendly content. Demonstrably strong writing ability, to be assessed via a writing sample A meticulous attention to detail, underscoring a commitment to accuracy and thoroughness in all aspects of work. Capable of functioning effectively within a team as well as independently. Preferred Qualifications Experience creating Nuclei templates. Practical experience with network and web application penetration testing tools, such as Burp Suite, Nmap, Fiddler, ZAP, Metasploit, and Wireshark. Familiarity with scripting and programming languages such as YAML, Python, Golang, JavaScript, C, etc. Prior experience within a quick reaction or incident response team environment. Familiarity with malware detections, including YARA, Sigma, and Snort. #J-18808-Ljbffr
-
Jr. Cyber Threat Analyst
1 week ago
Southern Manila District, Philippines HRTX Full timeYou will be reporting on technical subject matter such as malware developments, offensive security tools, vulnerability exploits, cloud security, and mobile security. Cyber Threat Analysts are expected to familiarize themselves with these topics continuously, identifying threat leads from a variety of sources. Cyber Threat Analysts are also expected to...
-
Vulnerability Remediation Engineer
2 weeks ago
Manila, Philippines Eze Castle Integration, Inc. Full timeManila PhilippinesTaguig City 1634, PHPPNS, PHL ECI is the leading global provider of managed services, cybersecurity, and business transformation for mid‑market financial services organisations across the globe. From its unmatched range of services, ECI provides stability, security and improved business performance, freeing clients from technology...
-
Software Security Engineer
6 days ago
Southern Manila District, Philippines Avaloq AG Full timeThe Avaloq Security team is an international team of analysts, senior and expert software engineers and architects. The Avaloq Security team develops and maintains central application security frameworks and tools for all companywide technology stacks and consults the business teams on best practice implementations for context specific security requirements....
-
Vulnerability Management Senior Manager
3 weeks ago
, Metro Manila, Philippines GCash Full timeJoin to apply for the Vulnerability Management Senior Manager role at GCash 3 days ago Be among the first 25 applicants Do you want to take the first step in making Filipinos’ lives better everyday? Here in GCash we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation! G...
-
Cyber Threat Analyst
3 weeks ago
Southern Manila District, Philippines HRTX Full timeResponsibilities Threat Lead Identification: Research new adversary tactics, techniques, and procedures (TTPs) using open sources (public information such as security vendor reporting, social media, code repositories); closed sources (dark web and underground forums); and proprietary sources. Subject Matter: Threat leads should focus on team priority...
-
Sr. Cyberthreat Analyst
1 week ago
Southern Manila District, Philippines HRTX Full timeResponsibilities Threat Lead Identification: Research new adversary tactics, techniques, and procedures (TTPs) using open sources (public information such as security vendor reporting, social media, code repositories); closed sources (dark web and underground forums); and proprietary sources. Subject Matter: Threat leads should focus on team priority...
-
Senior Cyber Security Analyst
2 hours ago
Manila, Philippines Vista Equity Partners Management, LLC Full timeAt Tribute Technology, we make end-of-life celebrations memorable, meaningful, and effortless through thoughtful and innovative technology solutions. Our mission is to help communities around the world celebrate life and pay tribute to those we love. Our comprehensive platform brings together software and technology to provide a fully integrated experience...
-
Firewall Revalidation Analyst
3 weeks ago
Manila, Philippines QBE Insurance Group Full timeFirewall Revalidation Analyst page is loadedFirewall Revalidation Analyst Apply locations PHI - Manila Cebu, Philippines time type Full time posted on Posted Yesterday job requisition id Primary Details Time Type: Full timeWorker Type: EmployeeThe Security Analyst is responsible for protecting the organization’s IT systems, networks, and data from cyber...
-
Security Analyst
3 weeks ago
, Metro Manila, Philippines Verifone Full timeJoin to apply for the Security Analyst role at Verifone Join to apply for the Security Analyst role at Verifone Get AI-powered advice on this job and more exclusive features. Why VerifoneFor more than 30 years Verifone has established a remarkable record of leadership in the electronic payment technology industry. Verifone has one of the leading electronic...
-
Security Analyst, Technology
3 weeks ago
Manila, Philippines Kroll Full timeOur professionals balance analytical skills, deep market insight and independence to deliver solid, defensible analysis and practical advice to our clients. As an organization, we think globally. We create transparency in an opaque world, and we encourage our people to do the same. That means when you take your place on our team, you’ll discover a...