Information Security Analyst at Hitss conducting penetration tests and security assessments across IT infrastructures. Collaborating with teams to report and mitigate vulnerabilities.
Responsibilities
Perform penetration tests on IT infrastructure, including networks, operating systems, servers and network devices, as well as web and mobile applications;
Execute penetration testing phases in accordance with established best practices, processes and methodologies;
Identify and exploit security vulnerabilities in systems, networks and applications using manual techniques and automated tools;
Prepare and present detailed penetration testing reports.
Requirements
Bachelor's degree in Cyber Defense, Computer Science, Information Systems or a related field;
Basic English proficiency;
Strong experience in offensive security projects (penetration testing);
Experience using methodologies such as OWASP, OSSTMM, NIST, PTES, among others;
Experience creating testing methods to identify and exploit vulnerabilities;
Experience finding security flaws in software (web applications and proprietary and open-source systems);
Experience documenting test results and discussing findings with internal and external teams;
Experience providing recommendations for vulnerability remediation;
Experience preparing and presenting detailed penetration testing reports;
Familiarity with tools such as proxies, port scanners, vulnerability scanners, exploit frameworks, Burp Suite, Nessus, Nmap, Metasploit;
Knowledge of computer networks (protocols);
Knowledge of operating system architecture (Windows and Linux);
Certifications such as CompTIA Security+, CompTIA PenTest+, EC-Council CEH, Desec.
Benefits
Gender and race/ethnicity equity
Positions eligible for professionals with disabilities
Cyber Risk Analyst assessing third - party vendor cybersecurity risks for S&P Global. Collaborating with teams to evaluate vendors' security postures and enhance risk management processes.
Information Security Analyst managing risk and compliance controls at USAA. Collaborating with key stakeholders to enhance information security and regulatory compliance processes.
Security Analyst managing security and compliance programs for fintech startup. Ensuring policies and evidence stay organized and collaborate with Head of Security for execution.
IT Security Analyst overseeing internal audits, security assessments, and compliance for CMC’s IT operations. Engaging in risk management and policy development while collaborating with cross - functional teams.
Specialist in PingFederate, PingDirectory and PingID for IAM infrastructure management. Collaborating with teams for stable operation and development in Cotia.
Senior Security Analyst developing and implementing security strategies for logistics operations. Focus on risk assessment, staff training, and policy compliance.
IT Security Analyst supporting the Supreme Court of Nevada in safeguarding judicial information systems. Implementing security controls, maintaining compliance, and conducting security assessments in a collaborative environment.