استخدام کارشناس تست نفوذ و امنیت
شرح موقعیت شغلی
Key Responsibilities:
• Design and implement information security policies, processes, and standards (ISO 27001, NIST, CIS, OWASP).
• Identify, analyze, and manage security threats and vulnerabilities.
• Manage and monitor SIEM platforms, firewalls, IDS/IPS, and other security tools.
• Conduct regular penetration tests, vulnerability assessments, and security audits.
• Lead incident response activities and coordinate recovery efforts.
• Raise organizational awareness by conducting security training programs for employees.
• Collaborate with IT, network, and development teams to embed security across all stages of projects.
• Prepare and deliver security reports and recommendations for senior management.
⸻
Required Technical Skills:
• Strong knowledge of network security concepts (Firewall, IDS/IPS, VPN, Proxy).
• Expertise in security protocols (TLS/SSL, IPsec, SSH).
• Familiarity with security standards and frameworks (ISO 27001, NIST, CIS Controls, OWASP Top 10).
• Hands-on experience in vulnerability assessment and penetration testing (VAPT).
• Proficiency with security tools such as Wireshark, Nmap, Burp Suite, Metasploit, Nessus, SIEM platforms.
• Log management and security event analysis.
• Knowledge of operating system security (Windows, Linux, Unix).
• Scripting/programming skills for automation (Python, Bash, PowerShell).
• Experience with cloud security (AWS, Azure, GCP).
• Knowledge of cryptography and multi-factor authentication (MFA) solutions.
⸻
Analytical & Managerial Skills:
• Strong incident response and forensics skills.
• Ability to conduct risk assessment and risk management.
• Security documentation and report preparation for leadership.
• Ability to conduct awareness and training programs for employees.
• Familiarity with data governance and privacy regulations (e.g., GDPR).
⸻
Preferred Qualifications:
• Relevant certifications such as CISSP, CISM, CEH, OSCP, ISO 27001 Lead Implementer.
• Experience in DevSecOps integration.
• Familiarity with compliance requirements in fintech or healthcare industries.
• Design and implement information security policies, processes, and standards (ISO 27001, NIST, CIS, OWASP).
• Identify, analyze, and manage security threats and vulnerabilities.
• Manage and monitor SIEM platforms, firewalls, IDS/IPS, and other security tools.
• Conduct regular penetration tests, vulnerability assessments, and security audits.
• Lead incident response activities and coordinate recovery efforts.
• Raise organizational awareness by conducting security training programs for employees.
• Collaborate with IT, network, and development teams to embed security across all stages of projects.
• Prepare and deliver security reports and recommendations for senior management.
⸻
Required Technical Skills:
• Strong knowledge of network security concepts (Firewall, IDS/IPS, VPN, Proxy).
• Expertise in security protocols (TLS/SSL, IPsec, SSH).
• Familiarity with security standards and frameworks (ISO 27001, NIST, CIS Controls, OWASP Top 10).
• Hands-on experience in vulnerability assessment and penetration testing (VAPT).
• Proficiency with security tools such as Wireshark, Nmap, Burp Suite, Metasploit, Nessus, SIEM platforms.
• Log management and security event analysis.
• Knowledge of operating system security (Windows, Linux, Unix).
• Scripting/programming skills for automation (Python, Bash, PowerShell).
• Experience with cloud security (AWS, Azure, GCP).
• Knowledge of cryptography and multi-factor authentication (MFA) solutions.
⸻
Analytical & Managerial Skills:
• Strong incident response and forensics skills.
• Ability to conduct risk assessment and risk management.
• Security documentation and report preparation for leadership.
• Ability to conduct awareness and training programs for employees.
• Familiarity with data governance and privacy regulations (e.g., GDPR).
⸻
Preferred Qualifications:
• Relevant certifications such as CISSP, CISM, CEH, OSCP, ISO 27001 Lead Implementer.
• Experience in DevSecOps integration.
• Familiarity with compliance requirements in fintech or healthcare industries.
مهارتهای مورد نیاز
- تست نفوذ
- امنیت
- مفاهیم شبکه
حداقل سابقه کار
- سه تا شش سال
جنسیت
- مهم نیست
وضعیت نظام وظیفه
- مهم نیست