Job Description
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Responsibilities:
Research, analyze, and assess attack surface and vulnerability dataDevelop tailored and actionable mitigation strategies and plans to address vulnerability riskWork with new and emerging vulnerability data to identify potential attack paths in critical systems.Document, develop and present mitigation strategies in web applications, databases, standalone applications, etc.Analyze the root cause of vulnerabilities and support the prioritization of mitigations based on risk and return on mitigationProvide mitigation strategies that prioritize risk against level of effort for multiple systems or organizationsCatalog mitigation advice, challenges, and trends and patternsPatch diffing and reverse engineering with tools such as Ghidra, IDA, etc.Provide subject matter expertise on tailored mitigations to resolve and remediate vulnerabilities on targeted technologiesWork in fast-paced startup like environment with shifting priorities to handle and maintain balance with multiple stakeholders.Conduct research to assess and create software patches and configuration changes to be applied to varied software, middleware and hardwareProvide assessment including security, system, and business impact of vulnerabilitiesMust be able to think ahead to avoid business outages based on the lab resultsAnalyze vulnerability data and support management of identified vulnerabilities, including tracking, remediation, and reportingDesired Skills:
Excellent understanding of network, system and application securityExperience with IDA Pro, Ghidra, or similar binary analysis toolKnowledge of various vulnerability scanning solutions is a plusExcellent written and verbal communicationGraduate with preferable 4 years degree or at least 3-year degree with computer science and information technology backgroundSecure architecture designs and use of detection/protection mechanisms (e.g., firewalls, IDS/IPS, full-packet capture technologies) to mitigate riskA solid understanding of industry best practices for Patch ManagementSpecific demonstrated experience mapping business processes and comparing those processes to industry best practicesBackground around using or understanding of security tools would be plusSolid understanding of the security implications of a patch on web applications, Windows, Linux, Mac OS operating systemsThorough testing of patches in a non-production environmentHave working knowledge of basic operation systems commands and tooling - Windows, Linux, Mac OSShould have very good communication and articulation skillsAbility and ready to learn new technology and should be a good team playerWhat you get to do:
Work within Threat Research, detection and response teams and analysts to define the priority, design the solution, and contribute to build framework for patching vulnerabilities
Apply for this Position
Ready to join ? Click the button below to submit your application.
Submit Application