Vulnerability Intelligence Researcher Full-time

at ThreatLandscape in Banglore (Published at 24-08-2018)

Who you are

• An analyst, a Red-Team-Blue-Team thinker, an autodidact, a threat hunter, or a researcher like none other

• An always-on Security enthusiast and the go-to for news and views about vulnerabilities and malware, active threats, attack vectors, and zero-days exploited in the wild

• An Eagle for detail and spotting the ‘known’ in the unknown

• Passionate about Cyber Security and a believer in defending against the bad guys

• Communicator at par in verbal, textual, and graphical mediums

• A Bachelor or Master of Engineering or Technology in Computers, Information Science, or Information Technology or a Master of Computer Applications

What you’ll do

• Work cross-functionally with Cyber Threat Intelligence and Cyber Security Operations teams to build out our ever-evolving threat intelligence platform

• Ideate and define ways to present vulnerability intelligence, preferably via dashboards and reports

• Identify factors contributing to higher client-side impact of vulnerabilities and be the domain expert for our impact scoring mechanism

• Track and monitor vulnerability lifecycles from zero-day discovery to CVE-ID allocation

• Profile and monitor specific cyber threat actors —- including nation-states and hacktivists —-, groups, and campaigns to understand adversarial tradecraft along with tactics, techniques and procedures (TTPs)

[BROWNIES] Clearly communicate findings in written reports in English and visuals

What you got

• Between two and five years’ experience in Cyber Security

• Hands-on understanding of vulnerabilities, computer intrusions, malicious code and patching mechanisms for Windows, Linux, and critical apps

• Working knowledge and understanding of CVSS v2 or v3 • Proven abilities to associate vulnerabilities with CWEs

• Able to analyze network protocols for vulnerability identification • Familiarity with network-based exploitation and its mitigation

• Familiarity with Snort and Suricata

[HUGE PLUS] Experience or familiarity with vulnerability assessments

