Penetration Tester Engineer Job at Certeon Technology - Career Opportunity in Kenya
Website :
1176 Days Ago
Linkedid Twitter Share on facebook

Vacancy title:
Penetration Tester Engineer

[ Type: FULL TIME , Industry: Information Technology , Category: Computer & IT ]

Jobs at:

Certeon Technology

Deadline of this Job:
20 September 2021  

Duty Station:
Within Kenya , Nairobi , East Africa

Summary
Date Posted: Tuesday, August 17, 2021 , Base Salary: Not Disclosed


JOB DETAILS:
Roles and Responsibilities
Security Engineer / Penetration Tester will provide penetration testing services for our new and existing client applications, network and infrastructure. The Security Engineer has to identify security weaknesses within client business environments, report on issues, provide technical advice and make recommendations for ongoing maintenance. The Security Engineer will identify security risks and requirements for new projects and system developments to ensure that NIST RMF or other security standards are met. The Security Engineer will help develop strategies to increase the reliability of system outputs, analyze and assess security for clients, and enhance systems security and integrity.
• Simulate adversarial threat-based approaches to expose and exploit vulnerabilities to protect Information Systems & Computer Networks.
• Maintain and suggests monitoring and analysis tools
• Create a security architecture and work with developers to ensure this architecture is part of the development cycle.
• Develop tools and solutions that allow organizations to prevent and respond effectively to attacks.
• Document procedures, requirements, and protocols.
• Developing a set of security standards and practices
• Recommending security enhancements
• Installing and using software, such as firewalls and data encryption programs
• Conducting scans of networks to find vulnerabilities
• Conducting penetration testing
• Monitoring networks and systems for security breaches or intrusions
• Developing automation scripts to handle and track incidents
• Leading incident response activities
• Helping plan an organization’s information security strategy Test and validate the effectiveness of customers’ IT security posture based on various security standards such as NIST SP 800-115.
• Participate in (Penetration and Social Engineering) client meetings required to document the requirements and produce a project Rules of Engagement (ROE).
• The ROE shall at a minimum, include the System Under Test (SUT), pentest activities, project time lines, communication plan, scope, project purpose, and the intended outcome and benefits of testing relating to the requestor’s security requirements
• Generate a Penetration Testing Technical Report (PTR) that will summarize the project within the Executive Summary and at a minimum, identify the high security risks, threats, and failures found during the project; have a detailed findings section detailing every finding with an overview, evidence, root cause analysis and recommended mitigation plan of action addressing each security issue; and will be delivered to the client.

Qualifications Required Education and Experience
• Bachelor's degree required. Computer Science, IT, Computer/Electrical Engineering
• Proven experience developing, operating and maintaining security systems
• Extensive knowledge of operating system and database security
• Proficiency in networking technologies (security, monitoring and solutions)
• Knowledge of security systems including anti-virus applications, content filtering, firewalls,
• In-depth knowledge of security protocols and principles
• Knowledge of Secure SDLC and security standards like OWASP, CWE, NIST, OSSTMM 5 Penetration Testing
• Proven experience in identifying and exploiting business logic and framework related vulnerabilities in removing false positives, analyzing dynamic scan webinspect, analyzing static scan tools, and appscan reports
• Certified training in information security e.g. CEH, CISSP, OSCP, COBIT or equivalent
• Experience working with RMF and NIST 800-53
• Experience with mobile application penetration tests on iOS and Android platforms Work Environment Required Certification Desired Certifications Acceptable Certifications Certified Ethical Hacker CISSP CSSP Analyst Penetration Testing

Work Hours: 8


Experience in Months: 36

Level of Education:
Bachelor Degree

 

{module 312}

Job application procedure
Email CV : hello@certeon.technology


All Jobs

QUICK ALERT SUBSCRIPTION

{module 316}

Job Info
Job Category: Computer/ IT jobs in Kenya
Job Type: Full-time
Deadline of this Job: 20 September 2021
Duty Station: Kenya
Posted: 17-08-2021
No of Jobs: 1
Start Publishing: 17-08-2021
Stop Publishing (Put date of 2030): 17-08-2065
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.