- Erfahrung
- 1–3 Jahre
- Gehalt
- —
- Stellenangebote
- 1
- Veröffentlicht
- vor 4 Stunden
- Arbeitsmodus
- Arbeiten von zu Hause
- Wieder aufnehmen
- Bewerbung erforderlich
Stellenbeschreibung
Role Overview
This opportunity is for an entry-level Information Security Analyst based in Canada, aimed at bolstering cybersecurity defenses through identification and mitigation of vulnerabilities. The role entails performing penetration testing, vulnerability analysis, and security assessments in varied technology settings. As part of the responsibilities, the analyst will engage in offensive security tasks, technical investigations, client interactions, and efforts toward continual enhancement of organizational security measures.
Key Responsibilities
- Execute vulnerability assessments and penetration tests on multiple platforms including web and mobile applications, cloud infrastructure, SaaS solutions, network hardware, and open-source software.
- Conduct both black-box and white-box testing to uncover vulnerabilities such as business logic flaws and technical gaps.
- Create, validate, and refine security rule sets for dynamic application security testing tools.
- Interpret security findings and offer clear, actionable guidance to clients for remediation efforts.
- Engage directly with clients via calls and written communication to discuss security concerns and remediation strategies.
- Assist clients in establishing structured remediation plans and enhancing overall security postures.
- Maintain and enhance vulnerability management processes and technologies.
- Keep abreast of the latest cybersecurity threats, tactics, and industry standards.
- Participate in the continuous improvement of security testing procedures and internal tooling.
Qualifications and Requirements
- Between one and three years of experience performing penetration testing or vulnerability assessments in diverse technological domains.
- Hands-on experience assessing security of web applications, cloud environments, SaaS platforms, or equivalent assets.
- Understanding of black-box and white-box testing methodologies.
- Capability to detect business logic vulnerabilities and evaluate complex security risks.
- Certifications such as CEH, OSCP, or CREST are advantageous.
- Proficiency in reading and comprehending at least one programming language.
- Strong analytical mindset and meticulous attention to technical details.
- Effective communication skills for customer interactions through telephone and email.
- A genuine enthusiasm for cybersecurity and a commitment to ongoing skill development.
- Experience with recognized CVEs, participation in bug bounty programs, or involvement in Capture The Flag competitions is considered a plus.
Benefits and Work Environment
- 100% remote work enabled with the flexibility to operate from any location.
- Engagement with real-world cybersecurity challenges and research projects.
- Exposure to sophisticated penetration testing and vulnerability management techniques.
- Collaborative environment within a startup focused on innovation and career development.
- Opportunities to demonstrate expertise and contribute to impactful security efforts.
- Learning and growth prospects in the fast-changing cybersecurity sector.
- Participation in team events and potential workcation experiences.
Additional Information
This vacancy is managed through a third-party partner who handles all applications and subsequent recruitment steps directly. The recruitment process includes the aid of AI to objectively match applicant qualifications to core job requirements, while all final hiring decisions are made by human recruiters. The employer adheres to applicable data protection laws and respects applicant privacy.