VAPT & Red Teaming Analyst
The Vulnerability Assessment Engineer is responsible for identifying, analyzing, and reporting security vulnerabilities across the organization's IT infrastructure, with a specific focus on integrating and securing new servers during their onboarding and commissioning phases using industry-leading tools like Qualys or Tenable.The Vulnerability Assessment Engineer is responsible for identifying, analyzing, and reporting security vulnerabilities across the organization's IT infrastructure, with a specific focus on integrating and securing new servers during their onboarding and commissioning phases using industry-leading tools like Qualys or Tenable.
- Execute regular and ad-hoc vulnerability scans across the enterprise network, applications, and systems using Qualys Vulnerability Management (VMDR) or Tenable.io/Nessus.
- Analyze scan results, prioritize vulnerabilities based on risk, and provide detailed reports to relevant stakeholders.
- Actively participate in the server commissioning process, ensuring all new servers are integrated into the vulnerability management program from day one.
- Perform initial baseline vulnerability assessments on newly provisioned servers before they enter production, identifying and reporting critical security gaps.
- Collaborate with server administrators and project teams to ensure identified vulnerabilities on new servers are remediated or mitigated according to security policies and timelines.
- Verify the secure configuration of new servers against established security baselines and compliance requirements.
- Work closely with IT operations, development, and system owners to facilitate the remediation of identified vulnerabilities.
- Track remediation efforts and re-scan systems to confirm the effectiveness of applied patches and configuration changes.
- Maintain, configure, and optimize vulnerability scanning platforms (Qualys or Tenable) to ensure accurate and comprehensive coverage.
- Develop and refine scanning policies, profiles, and reporting templates.
- Generate comprehensive vulnerability reports, dashboards, and metrics for various audiences, including technical teams and management.
- Maintain accurate documentation of vulnerability assessment processes, findings, and remediation activities.
Must-Have:
- Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field.
- Up to 4-7 years of experience in cybersecurity, with a strong focus on vulnerability management or security operations.
- Demonstrable hands-on experience with either Qualys (VMDR, Cloud Agent) or Tenable (Nessus, Tenable.io, Security Center) platforms.
- Solid understanding of network protocols, operating systems (Windows, Linux), and common enterprise applications.
- Familiarity with security frameworks and standards (e.g., NIST, ISO 27001, CIS Benchmarks).
Nice-to-Have:
- Strong analytical and problem-solving skills, with attention to detail.
- Excellent written and verbal communication skills, capable of explaining complex technical issues to both technical and non-technical audiences.
- Ability to prioritize tasks, manage multiple projects, and work effectively in a fast-paced environment.
- Scripting skills (e.g., Python, PowerShell) for automation and data analysis are a plus.