Var Group España logo
Var Group España

El Partner Tecnológico en tu transformación digital.

Senior Offensive Security Analyst

Security AnalystSecurity AnalystFull TimeRemoteSeniorTeam 201-500H1B No SponsorCompany SiteLinkedIn

Location

Spain

Posted

78 days ago

Salary

0

Seniority

Senior

Bachelor Degree5 yrs expSpanishEnglishAWSAzureGCPGraphQLLinuxPython

Job Description

Senior Offensive Security Analyst

Var Group España

• Serás responsable de planificar, ejecutar y supervisar pruebas de seguridad ofensiva avanzadas (Red Team, pentesting, simulaciones de adversarios, etc.) con el fin de identificar vulnerabilidades y evaluar la resiliencia de los sistemas frente a amenazas reales. • Diseñar y ejecutar campañas de Red Team y ejercicios de emulación de adversarios. • Realizar pruebas de penetración avanzadas en redes, aplicaciones web, APIs, APPs y entornos cloud. • Analizar y explotar vulnerabilidades complejas, incluyendo escalada de privilegios y movimientos laterales. • Colaborar con equipos Blue Team y de ingeniería para mejorar la postura defensiva. • Elaborar informes técnicos y ejecutivos con hallazgos, evidencias y recomendaciones. • Asesorar sobre medidas de mitigación y endurecimiento de sistemas. • Participar en la formación interna sobre técnicas ofensivas y tendencias de ciberataques.

Job Requirements

  • Grado en Informática, Ingeniería de telecomunicaciones o equivalente.
  • Tener formaciones y/o certificaciones específicas en ciberseguridad/seguridad ofensiva serán un nice-to-have (OSCP, OSEP, OSCE, CRTO, eCPTX, eCPTXv2 o similar).
  • Más de 5 años de experiencia en seguridad ofensiva, Red Team o pentesting, seguridad en la nube (Azure, AWS, GCP), análisis de seguridad en APIs REST y GraphQL, criptografía aplicada y protocolos de seguridad, aplicaciones móviles y ejercicios de RedTeam.
  • Experiencia comprobada en pentesting y análisis de vulnerabilidades.
  • Conocimientos avanzados en scripting (Python, Bash, PowerShell).
  • Dominio de herramientas como Burp Suite, Nessus, Metasploit, MobSF, Nmap, etc.
  • Familiaridad con frameworks como OWASP WSTG, CIS Benchmarks y NIST.
  • Conocimiento avanzado en seguridad de redes, sistemas operativos (Windows/Linux) y aplicaciones web.
  • Ingles: B2+. (We'll check your level at the interview, so be prepared to talk🗣)

Benefits

  • Plan de Compensación Flexible: tarjeta comida, tarjeta transporte, seguro médico y formación.
  • Conciliación de la vida laboral y familiar: flexibilidad horaria.

Related Job Pages

More Security Analyst Jobs

Enea AB logo

Security Analyst

Enea AB

We make the world’s communications safer and more efficient.

Security Analyst78 days ago
Full TimeRemoteTeam 501-1,000H1B No Sponsor

• Create and maintain security solutions on Enea client platform • Keep up to date with the telecoms threat landscape • Analyse data collected from customer deployments to identify and investigate threats • Provide security reviews for Enea clients; independently field client questions and manage client expectations. • Work on your own initiative, with minimal supervision, but with the support of a team lead and global team of analysts. • Some shift work (Saturday or Sunday) will be required for this role.

Mexico
Job Closed
ICF logo

Cybersecurity Strategist

ICF

We are not a typical consulting firm and our people are not typical consultants.

Security Analyst78 days ago
Full TimeHybridTeam 5,001-10,000Since 1969H1B Sponsor

Support strategic collaboration initiatives with industry partners, engage stakeholders, develop operational plans, and coordinate cyber defense exercises to enhance critical infrastructure and improve the cybersecurity ecosystem.

District Of Columbia + 2 moreAll locations: District Of Columbia | Virginia | Maryland
Job Closed
Full TimeRemoteTeam 51-200

Role Description As a Certified CCA Assessor, you’ll work with leading manufacturing, IT, Cloud, professional service organizations, and the Defense Industrial Base (DIB) serving the United States Department of Defense (DOD). You will be part of a team that supports the efforts of these organizations to satisfy DOD's Cybersecurity Maturity Model Certification and related government regulations as an assessor to certify organizations’ compliance with CMMC requirements. All CMMC Assessor positions are full time remote. Occasional or limited travel may vary based on client needs. What you'll do - Support assessing whether members of the DIB have adequately prepared for compliance with CMMC regulations. - Evaluate an organization’s readiness for assessment, which includes tasks such as: - Collect and examine evidence, observe, test and analyze results. - Clearly and effectively score OSC practices and validate preliminary results. - Generate preliminary report findings. - Finalize findings for an assessment report and deliver recommended assessment results. Qualifications - Working knowledge of the controls and implementation of DFARS Clause 252.204-7012 (NIST 800-171). - Direct involvement with building reports that clearly communicate met and not met objectives in accordance with assessment guidelines. - Ability to track detailed tasks and ensure timely delivery of project deliverables. - Excellent communication and problem-solving skills. - Critical thinking, and ability to balance security requirements with mission needs. - Must be well-organized and detail-oriented with the ability to coordinate, prioritize multiple tasks, and be adaptable to change to accomplish assignments. - Ability to work independently and as a part of a team. - Professional and polished interpersonal and communication skills with team members and stakeholders. - Hands-on security and consulting experience. Requirements - Completed Bachelor’s degree from an accredited university, preferably in an IT related field. - US Citizenship Required. - Currently possess completed Tier 3 Suitability with the Cyber AB. - Required: Completed CCA Certification, with completed/active Tier 3 Suitability with the Cyber AB. - Minimum 5 to 7 years of overall experience in the IT Security / Cybersecurity industry. - Overall 3 years in a Client facing role providing risk assessment, advisory services, and/or consulting - ideally in a federal environment. - Previous experience working for a CMMC RPO or C3PAO (Candidate or Authorized), or other 3PAO assessments is preferred. Bonus Points - Additional cybersecurity certifications and experience highly desired (i.e., CISSP, CISM). - Experience with NIST 800-37, NIST 800-53, and FISMA. - Experience with FedRAMP assessments and cloud security. - DIB experience. Benefits - Paid parental leave. - Flexible time off. - Certification and training reimbursement. - Digital mental health and wellbeing support memberships. - Comprehensive insurance options.

United States

Security Analyst

Thinkahead Consultant Psychologist Pty Ltd

We get to the heart of the matter.....real people......real solutions

Security Analyst78 days ago
Full TimeRemoteTeam 1-10H1B No Sponsor

• SOC Analysts at AHEAD monitor customer environments and perform Incident Detection, Validation, and Incident Reporting. • SOC Analysts are responsible for triaging events, incidents, and reporting validated incidents to the customer for incident response. • Perform troubleshooting of customer issues. • Monitor security feeds streaming from client servers, network devices, and end user workstations. • Operate and maintain network security equipment at client locations. • Perform information security event analysis and must possess knowledge of operating systems, TCP/IP networking, network attacks, vulnerability management, and log analysis.

India