Var Group España logo
Var Group España

El Partner Tecnológico en tu transformación digital.

Senior Offensive Security Analyst

Security AnalystSecurity AnalystFull TimeRemoteSeniorTeam 201-500H1B No SponsorCompany SiteLinkedIn

Location

Spain

Posted

125 days ago

Salary

0

Seniority

Senior

Bachelor Degree5 yrs expSpanishEnglishAWSAzureGCPGraphQLLinuxPython

Job Description

Senior Offensive Security Analyst

Var Group España

• Serás responsable de planificar, ejecutar y supervisar pruebas de seguridad ofensiva avanzadas (Red Team, pentesting, simulaciones de adversarios, etc.) con el fin de identificar vulnerabilidades y evaluar la resiliencia de los sistemas frente a amenazas reales. • Diseñar y ejecutar campañas de Red Team y ejercicios de emulación de adversarios. • Realizar pruebas de penetración avanzadas en redes, aplicaciones web, APIs, APPs y entornos cloud. • Analizar y explotar vulnerabilidades complejas, incluyendo escalada de privilegios y movimientos laterales. • Colaborar con equipos Blue Team y de ingeniería para mejorar la postura defensiva. • Elaborar informes técnicos y ejecutivos con hallazgos, evidencias y recomendaciones. • Asesorar sobre medidas de mitigación y endurecimiento de sistemas. • Participar en la formación interna sobre técnicas ofensivas y tendencias de ciberataques.

Job Requirements

  • Grado en Informática, Ingeniería de telecomunicaciones o equivalente.
  • Tener formaciones y/o certificaciones específicas en ciberseguridad/seguridad ofensiva serán un nice-to-have (OSCP, OSEP, OSCE, CRTO, eCPTX, eCPTXv2 o similar).
  • Más de 5 años de experiencia en seguridad ofensiva, Red Team o pentesting, seguridad en la nube (Azure, AWS, GCP), análisis de seguridad en APIs REST y GraphQL, criptografía aplicada y protocolos de seguridad, aplicaciones móviles y ejercicios de RedTeam.
  • Experiencia comprobada en pentesting y análisis de vulnerabilidades.
  • Conocimientos avanzados en scripting (Python, Bash, PowerShell).
  • Dominio de herramientas como Burp Suite, Nessus, Metasploit, MobSF, Nmap, etc.
  • Familiaridad con frameworks como OWASP WSTG, CIS Benchmarks y NIST.
  • Conocimiento avanzado en seguridad de redes, sistemas operativos (Windows/Linux) y aplicaciones web.
  • Ingles: B2+. (We'll check your level at the interview, so be prepared to talk🗣)

Benefits

  • Plan de Compensación Flexible: tarjeta comida, tarjeta transporte, seguro médico y formación.
  • Conciliación de la vida laboral y familiar: flexibilidad horaria.

Related Job Pages

More Security Analyst Jobs

Enea AB logo

Security Analyst

Enea AB

We make the world’s communications safer and more efficient.

Security Analyst125 days ago
Full TimeRemoteTeam 501-1,000H1B No Sponsor

• Create and maintain security solutions on Enea client platform • Keep up to date with the telecoms threat landscape • Analyse data collected from customer deployments to identify and investigate threats • Provide security reviews for Enea clients; independently field client questions and manage client expectations. • Work on your own initiative, with minimal supervision, but with the support of a team lead and global team of analysts. • Some shift work (Saturday or Sunday) will be required for this role.

Mexico
Job Closed
ICF logo

Cybersecurity Strategist

ICF

Founded in 1969, ICF is a global advisory and technology services company headquartered in Reston, Virginia. It delivers data-driven solutions across energy, en

Security Analyst125 days ago

Support strategic collaboration initiatives with industry partners, engage stakeholders, develop operational plans, and coordinate cyber defense exercises to enhance critical infrastructure and improve the cybersecurity ecosystem.

District Of Columbia + 2 moreAll locations: District Of Columbia | Virginia | Maryland
Job Closed

Security Analyst

Thinkahead Consultant Psychologist Pty Ltd

We get to the heart of the matter.....real people......real solutions

Security Analyst126 days ago
Full TimeRemoteTeam 1-10H1B No Sponsor

• SOC Analysts at AHEAD monitor customer environments and perform Incident Detection, Validation, and Incident Reporting. • SOC Analysts are responsible for triaging events, incidents, and reporting validated incidents to the customer for incident response. • Perform troubleshooting of customer issues. • Monitor security feeds streaming from client servers, network devices, and end user workstations. • Operate and maintain network security equipment at client locations. • Perform information security event analysis and must possess knowledge of operating systems, TCP/IP networking, network attacks, vulnerability management, and log analysis.

India

Role Description Apkudo’s growth has hit a pivotal point of requiring a dedicated person to take over the more technical aspects of our information security management system and certifications. This role is part of our Apkudo Compliance Team whose mission is to drive a commitment and culture of improvement that ensures we maintain a high level and recognizable standard of compliance, quality and ethics. If you have proven professional experience, detailed knowledge of information security auditing, and want to make Apkudo more productive and efficient, this is the role and place for you! Apply today! Qualifications - Professional experience in information security auditing with a focus on SOC 1 & 2 standards - Detailed knowledge of ISO 27001 standard, ISO Certification Process Audits, and SOC 1 and 2 standards - Experience with AWS and Google Workspace - Strong analytical problem-solving skills and attention to detail - Excellent verbal and written communication skills, as well as strong partnership skills - Experience with cybersecurity and auditing, preferably with 3-5 years of experience - Degree in Computer Science, Computer Engineering, IT, or similar field, or 3+ years of IT security or cybersecurity related work experience Requirements - Manage and enforce Apkudo's SOC 1 & 2 Controls, ensuring that all security practices are compliant with industry standards - Be the main point of contact and liaison with external SOC auditors, facilitating effective communication and resolution of audit findings - Perform regular internal audits for SOC and ISO controls, identifying areas for improvement and ensuring that corrective actions are implemented - Lead the Compliance member of our Information Security Council, driving security awareness and training for key security focuses throughout the organization - Monitor and resolve alerts and alarms in critical systems, ensuring that potential security threats are identified and mitigated promptly - Manage security event responses and investigations, providing timely and effective resolution to security incidents - Coordinate regular penetration testing and drive improvement actions, ensuring that Apkudo's security posture is maintained and improved - Be the company administrator for password and phishing management systems, ensuring that security policies and procedures are up-to-date and compliant - Review and update security-related policies and procedures to ensure alignment with industry standards and best practices - Drive awareness and training of key security focuses throughout the organization, ensuring that all employees are equipped to maintain a high level of security awareness - Assist and support company stakeholders with questions regarding information security, providing timely and effective guidance and support - Stay up-to-date with the latest information security management trends and best practices, applying this knowledge to drive security improvements within Apkudo - Work with Legal to identify and ensure compliance with cryptographic and data encryption regulations - Participate in ad-hoc projects related to improving Apkudo's security posture, applying a collaborative and flexible approach to drive security improvements

United States
Job Closed