- Identify vulnerabilities and exposure withinenterprise networks, systems, and applications.
- Lead or enable exploitation operations insupport of organization objectives and target requirements.
- Perform technical (evaluation of technology) andnontechnical (evaluation of people and operations) risk and vulnerabilityassessments of relevant technology focus areas (e.g., local computingenvironment, network and infrastructure, enclave boundary, supportinginfrastructure, and applications).
- Provide recommendations regarding the selectionof cost-effective security controls to mitigate risk (e.g., protection ofinformation, systems, and processes).
- Provide technical documents, incident reports,video recorded descriptions, findings from computer examinations, summaries,and other situational awareness information to relevant stakeholders.
- Conduct and/or support authorized penetrationtesting on enterprise network assets and perform penetration testing as required for newor updated applications.
- Review the security status of a system(including the effectiveness of security controls) on an ongoing basis todetermine whether the risk remains acceptable.
- Provide recommendations for how to improve thecontrols based on test scenario findings and create and conduct custom tabletop exercises.
- Partner with other teams on alert development tocreate new alerts and identify gaps in alerting.
- Develop your own test scenarios by performingthreat hunts and ethical hack tests and analyze Threat Trends to identify indicators ofcompromise (IOCs).
- Design and develop new tools/technologiesrelated to cybersecurity and identify control gaps that allow threats toenter our network.
- Develop specific cybersecurity countermeasuresand risk mitigation strategies for systems and/or applications.
- Exploit network devices, security devices,and/or terminals or environments using various methods or tools.
- Create comprehensive exploitation strategiesthat identify exploitable technical or operational vulnerabilities, and test and evaluate locally developed tools foroperational use.
- Identify functional- and security-relatedfeatures to find opportunities for new capability development to exploit ormitigate vulnerabilities.
- Perform analysis for target infrastructureexploitation activities and conduct exploitation of wireless computers anddigital networks.
- Analyze identified malicious activity todetermine weaknesses exploited, exploitation methods, effects on system and information.
Requirements
- Bachelor's Degree in Computer Science, Information Technology, Electrical & Electronic Engineering, or a related discipline from a reputable higher institution.
- 3+ years experience in a similar role, preferably in a Fin-tech or financial services industry.
- Experience leading projects and mentoring junior team members will be a plus.
- Strong analytical, planning, organization, and problem-solving skills.
- Excellent communication and interpersonal skills, and ability to work independently and as part of a team.
- Experience with web security, application security, and strong red team security experience is essential.
Benefits
Qore provides the rareopportunity to make history in the financial space for Africa by Africans,while working with the smartest, brightest & coolest minds in Africa. Ourpeople & culture team continuously thinks of innovative ways to improve employeeexperience and some of the other benefits of working with Qore includes:
- Very Competitive & Rewarding Pay
- Flexible work option (i.e., Remote)
- Paid Lunch for onsite work
- Lifelong Learnings
Learn more about this Employer on their Career Site
