Job Openings
Vulnerability Consultant – Attack Surface Management
About the job Vulnerability Consultant – Attack Surface Management
Key Responsibilities
This is an opportunity to work in a fun and challenging environment, using market-leading security testing tools and platforms to provide security testing services to our large client base. You will play a key role in delivering and managing client security programs all year round, as well as building relationships with clients and ensuring that our services are meeting their needs. You will also have the responsibility of working within the senior TAM team to support the direction and development of new service lines offered by the company.
- Line Management of a small Vulnerability Management team
- Setting up security programs with clients based on their requirements
- Running and verifying network and application vulnerability scans
- Writing and delivering client reports
- Analysis of external and internal attack surface outputs to identify and communicate risk
- Work directly with customers to provide prioritization for remediation
- Providing support and answering queries from clients
- Act as the customer advocate within the Attack Surface Management Team
- Own the operational relationships with your customers
- Identifying efficiency and process improvements for the operational teams.
- Act as the SME to customers to improve the quality of service they are receiving and maintain a roadmap for those customers
- Assist with the onboarding of new customers, building an understanding of customers business risks
- Lead and mentor more junior consultants and analysts, providing guidance and support in delivering exceptional service to our clients.
- Foster a collaborative and positive team culture, promoting knowledge sharing and continuous improvement.
- Work with the Departmental Leadership team, as a SME, to ensure success
Technical Skills & Knowledge
- Excellent understanding of basic cybersecurity principles
- Excellent understanding and experience of Linux and Windows operating systems
- Excellent understanding and exposure to network and web application security
- Strong experience using network and application scanning tools and utilities, such as Nexpose Rapid 7, Qualys, HP WebInspect, IBM AppScan, Tenable Nessus, Burp, NMAP, etc.
- Good understanding how vulnerabilities can be linked and the impact on risk
- Strong understanding of how to identify vulnerabilities that may be higher risk than their score indicates
- Experience of EASM platforms such as Cycognito
- Experience of ITSMs such as ServiceNow
- Strong interpersonal and communication skills
- Ability to work and manage time and tasks independently
- Ability to communicate with customers in a clear and concise manner
- Strong customer handling skills
- Good consultancy skills
Client Relationship Management
- Build and maintain strong relationships with key clients, serving as their trusted advisor for a range of ASM solutions.
- Conduct regular meetings with clients to understand their evolving requirements, address concerns, and identify opportunities for improvement.
- Collaborate with the sales team to identify upsell and cross-sell opportunities based on clients' ASM needs.
Desirable competencies:
- Degree in Computer Science/Engineering or equivalent experience
- Strong Experience in Information Security
- CRT and/or IASME Vulnerability assessment Plus certification
- Understanding of web services architecture and commonly employed technologies
- Exposure to software development and understanding of secure code development
- Knowledge and understanding of PCI DSS requirements, in particular PCI ASV testing
- Knowledge and understanding of Cyber Essentials requirements
- Understanding of DDoS Mitigation
- Experience with Python
- Experience with Java
- Understanding of ServiceNow
- UK Security Check (SC) clearance is desirable but not essential
K