Cybersecurity Specialist
Summary
Hands-on role focused on penetration testing, security monitoring, and vulnerability management. The specialist conducts assessments across web apps, APIs, and enterprise infrastructure (Azure, AWS, Active Directory) while managing SIEM platforms and supporting cybersecurity governance and compliance.
Job Purpose
We are seeking a hands-on Cybersecurity Specialist with strong experience in penetration testing, security monitoring, vulnerability management, and cybersecurity governance. The ideal candidate should have a strong security background while also being comfortable working with enterprise infrastructure, SIEM platforms, cloud environments, servers, Active Directory, and web applications.
Key Responsibilities
•Conduct penetration testing and security assessments of web applications, APIs, networks, servers, Active Directory environments, and other enterprise systems.
•Identify vulnerabilities, assess their risk and exploitability, and provide practical remediation recommendations.
•Perform manual penetration testing, including assessments against OWASP Top 10 and OWASP API Security Top 10 risks.
•Monitor and investigate security events and alerts through SIEM and security monitoring platforms.
•Support security incident investigation, response, containment, remediation, and post-incident improvement activities.
•Develop and tune SIEM alerts, detection rules, dashboards, and monitoring use cases.
•Support vulnerability management and coordinate remediation activities with infrastructure and development teams.
•Review the security of Microsoft Azure and AWS environments.
•Review Microsoft Azure and AWS environments and support the implementation of appropriate identity, network, logging, workload, and configuration security controls.
•Review and strengthen Microsoft Active Directory and Entra ID security, including privileged access, service accounts, authentication controls, Group Policy, and identity-related risks.
•Support the implementation and operation of protective technologies such as endpoint security, web application firewalls, SIEM, vulnerability management, and identity security controls.
•Participate in security reviews of new applications, systems, infrastructure, and technology projects.
•Support cybersecurity governance, risk assessments, policies, standards, compliance activities, and security audits.
•Work closely with infrastructure, software development, networking, and other IT teams to improve the organization's overall security posture.