Vulnerability Consultant – Attack Surface Management

2 weeks ago


Taguig, Philippines HRTX Full time
Vulnerability Consultant – Attack Surface Management

Job Openings Vulnerability Consultant – Attack Surface Management

About the job Vulnerability Consultant – Attack Surface Management

Key Responsibilities

This is an opportunity to work in a fun and challenging environment, using market-leading security testing tools and platforms to provide security testing services to our large client base. You will play a key role in delivering and managing client security programs all year round, as well as building relationships with clients and ensuring that our services are meeting their needs. You will also have the responsibility of working within the senior TAM team to support the direction and development of new service lines offered by the company.

  • Line Management of a small Vulnerability Management team
  • Setting up security programs with clients based on their requirements
  • Running and verifying network and application vulnerability scans
  • Writing and delivering client reports
  • Analysis of external and internal attack surface outputs to identify and communicate risk
  • Work directly with customers to provide prioritization for remediation
  • Providing support and answering queries from clients
  • Act as the customer advocate within the Attack Surface Management Team
  • Own the operational relationships with your customers
  • Identifying efficiency and process improvements for the operational teams.
  • Act as the SME to customers to improve the quality of service they are receiving and maintain a roadmap for those customers
  • Assist with the onboarding of new customers, building an understanding of customers business risks
  • Lead and mentor more junior consultants and analysts, providing guidance and support in delivering exceptional service to our clients.
  • Foster a collaborative and positive team culture, promoting knowledge sharing and continuous improvement.
  • Work with the Departmental Leadership team, as a SME, to ensure success

Technical Skills & Knowledge

  • Excellent understanding of basic cybersecurity principles
  • Excellent understanding and experience of Linux and Windows operating systems
  • Excellent understanding and exposure to network and web application security
  • Strong experience using network and application scanning tools and utilities, such as Nexpose Rapid 7, Qualys, HP WebInspect, IBM AppScan, Tenable Nessus, Burp, NMAP, etc.
  • Good understanding how vulnerabilities can be linked and the impact on risk
  • Strong understanding of how to identify vulnerabilities that may be higher risk than their score indicates
  • Experience of EASM platforms such as Cycognito
  • Experience of ITSMs such as ServiceNow
  • Strong interpersonal and communication skills
  • Ability to work and manage time and tasks independently
  • Ability to communicate with customers in a clear and concise manner

Client Relationship Management

  • Build and maintain strong relationships with key clients, serving as their trusted advisor for a range of ASM solutions.
  • Conduct regular meetings with clients to understand their evolving requirements, address concerns, and identify opportunities for improvement.
  • Collaborate with the sales team to identify upsell and cross-sell opportunities based on clients' ASM needs.
  • Degree in Computer Science/Engineering or equivalent experience
  • Strong Experience in Information Security
  • CRT and/or IASME Vulnerability assessment Plus certification
  • Understanding of web services architecture and commonly employed technologies
  • Exposure to software development and understanding of secure code development
  • Knowledge and understanding of PCI DSS requirements, in particular PCI ASV testing
  • Knowledge and understanding of Cyber Essentials requirements
  • Understanding of DDoS Mitigation
  • Experience with Python
  • Experience with Java
  • Understanding of ServiceNow
  • UK Security Check (SC) clearance is desirable but not essential
#J-18808-Ljbffr

  • Taguig, Philippines HR TechX Corp. Full time

    This is an exciting opportunity to join a dynamic security solutions team in which you will be responsible for the management and delivery of client security programs as well as playing a vital part in the development of the team and its services. As part of a passionate delivery team, you must have a passion for IT security as well as a determination to...


  • Taguig, Philippines HRTX Full time

    This is an opportunity to work in a fun and challenging environment, using market-leading security testing tools and platforms to provide security testing services to our large client base. You will play a key role in delivering and managing client security programs throughout the year, building relationships with clients, and ensuring our services meet...


  • Taguig, Philippines HRTX Full time

    Security Vulnerability and Penetration Testing (VAPT) Engineer Job Openings Security Vulnerability and Penetration Testing (VAPT) Engineer About the job Security Vulnerability and Penetration Testing (VAPT) Engineer Role Purpose To oversee and serve as a technical resource for all assessment activity related to the security posture of existing and proposed...


  • Taguig, Philippines B&M Global Services Manila Full time

    Security Vulnerability and Penetration Testing Engineer Join to apply for the Security Vulnerability and Penetration Testing Engineer role at B&M Global Services Manila The Security Vulnerability and Penetration Testing Engineer will oversee and serve as a technical resource for all assessment activities related to the security posture of existing and...


  • Taguig, Philippines Baker McKenzie Full time

    Overview Join to apply for the Security Vulnerability and Penetration Testing Engineer role at Baker McKenzie . Responsibilities Perform security penetration testing of the Firm’s systems, platforms, and applications Serve as a Subject Matter Expert (SME) for the VAPT function Serve as the system owner for common VAPT toolsets, platforms, and processes...


  • Taguig, Philippines Tata Consultancy Services Full time

    Vulnerability Remediation & Data Analysis Qualifications: Bachelor's degree in Computer Science, Information Technology, or a related field. 3+ years of experience in IT, with a focus on desktop engineering and vulnerability remediation. Strong understanding of workstation operating systems (Windows, macOS) and security vulnerabilities. Experience...

  • Security Engineer

    4 weeks ago


    Taguig, Philippines Hrtx Full time

    About the Role We are looking for a skilled Web & API Security Engineer with strong offensive security expertise. In this hands-on role, you will test modern web applications and APIs to find vulnerabilities, simulate real-world attacks, and work with engineering teams to improve our platforms security. What Youll Do Perform manual security testing on web...


  • Taguig, Philippines Willis Towers Watson Full time

    Description A penetration tester is responsible for assessing the security of web applications and its underlying infrastructure to identify vulnerabilities and weaknesses that could be exploited by attackers. Their role involves conducting thorough assessments and penetration tests to uncover potential security risks and provide recommendations for...


  • Taguig, Philippines WTW Full time

    Talent Acquisition - Sr. Technology Recruiter at WTW Location: WTW Taguig, National Capital Region, Philippines Description A penetration tester is responsible for assessing the security of web applications and its underlying infrastructure to identify vulnerabilities and weaknesses that could be exploited by attackers. Their role involves conducting...


  • Taguig, Philippines ECI Full time

    ECI is the leading global provider of managed services, cybersecurity, and business transformation for mid-market financial services organizations across the globe. From its unmatched range of services, ECI provides stability, security and improved business performance, freeing clients from technology concerns and enabling them to focus on running their...