VAPT & Red Team Expert

Open 34d posting dated last week · reposted 2× · 2 open copies

The Vulnerability Assessment Engineer is responsible for identifying, analyzing, and reporting security vulnerabilities across the organization's IT infrastructure, with a specific focus on integrating and securing new servers during their onboarding and commissioning phases using industry-leading tools like Qualys or Tenable.The Vulnerability Assessment Engineer is responsible for identifying, analyzing, and reporting security vulnerabilities across the organization's IT infrastructure, with a specific focus on integrating and securing new servers during their onboarding and commissioning phases using industry-leading tools like Qualys or Tenable.

  • Execute regular and ad-hoc vulnerability scans across the enterprise network, applications, and systems using Qualys Vulnerability Management (VMDR) or Tenable.io/Nessus.
  • Analyze scan results, prioritize vulnerabilities based on risk, and provide detailed reports to relevant stakeholders.
  • Actively participate in the server commissioning process, ensuring all new servers are integrated into the vulnerability management program from day one.
  • Perform initial baseline vulnerability assessments on newly provisioned servers before they enter production, identifying and reporting critical security gaps.
  • Collaborate with server administrators and project teams to ensure identified vulnerabilities on new servers are remediated or mitigated according to security policies and timelines.
  • Verify the secure configuration of new servers against established security baselines and compliance requirements.
  • Work closely with IT operations, development, and system owners to facilitate the remediation of identified vulnerabilities.
  • Track remediation efforts and re-scan systems to confirm the effectiveness of applied patches and configuration changes.
  • Maintain, configure, and optimize vulnerability scanning platforms (Qualys or Tenable) to ensure accurate and comprehensive coverage.
  • Develop and refine scanning policies, profiles, and reporting templates.
  • Generate comprehensive vulnerability reports, dashboards, and metrics for various audiences, including technical teams and management.
  • Maintain accurate documentation of vulnerability assessment processes, findings, and remediation activities.

Must-Have:

  • Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field.
  • Up to 8-12 years of experience in cybersecurity, with a strong focus on vulnerability management or security operations.
  • Demonstrable hands-on experience with either Qualys (VMDR, Cloud Agent) or Tenable (Nessus, Tenable.io, Security Center) platforms.
  • Solid understanding of network protocols, operating systems (Windows, Linux), and common enterprise applications.
  • Familiarity with security frameworks and standards (e.g., NIST, ISO 27001, CIS Benchmarks).

Nice-to-Have:

  • Strong analytical and problem-solving skills, with attention to detail.
  • Excellent written and verbal communication skills, capable of explaining complex technical issues to both technical and non-technical audiences.
  • Ability to prioritize tasks, manage multiple projects, and work effectively in a fast-paced environment.
  • Scripting skills (e.g., Python, PowerShell) for automation and data analysis are a plus.