Source description
About the role
As a Cyber Security Analyst specializing in Penetration Testing, your role involves performing security assessments for applications, infrastructure, and emerging technologies. You will guide product/service teams in secure design and implementation of IT systems. Your key responsibilities will include: - Performing penetration tests for high-risk Enterprise IT assets. - Gaining an understanding of the business process application architecture, IT infrastructure, and interaction with external entities. - Collaborating with the PDO team to define and agree on the scope of the test. - Conducting Pen testing for web/mobile applications to verify security implementation and identify vulnerabilities. - Assessing the risk of identified vulnerabilities, proposing countermeasures, and documenting technical findings and recommendations for non-technical stakeholders. - Following security governance processes for issue tracking and closure. - Using Standard Operating Procedures (SOP) for securely conducting penetration testing studies. - Developing, testing, and maintaining custom security testing scripts for vulnerability testing. - Promoting awareness of security issues among application and business teams through training programs. - Staying up to date with the latest security trends, tools, and techniques to enhance penetration testing skills. Your skillset should include: - Experience in Penetration Testing processes and tools, with a specialization in web, mobile applications, and API services. - Knowledge of security assessment, risk management processes, cyber security threats, vulnerabilities, and attack methods. - Familiarity with industry frameworks for penetration testing like OWASP, PTES, MITRE ATT&CK, Metasploit. - Ability to understand complex information system architecture and business processes to develop attack methods. - Experience in deploying various attack methods and techniques such as DDoS, brute force, spoofing, injection attacks, etc. - Knowledge and experience in applying cryptography, computer networking concepts, protocols, network security methodologies, cloud security, API security, AI security, and identity/access management systems. - Understanding of organizations' information security policies, standards, procedures, laws, regulations, policies, and ethics related to cybersecurity and privacy. - Excellent analytical, communication, documentation, and presentation skills. - Knowledge of emerging technologies like AI/ML, Zero Trust, LCNC, etc., with a willingness to learn new technologies and concepts. Qualifications required: - Bachelor's degree in computer science, Cyber Security, or a related field of study. - 2 years of experience in Cyber Security or related fields of IT. - Knowledge of Penetration Testing Frameworks such as OWASP, MITRE ATT&CK, Metasploit, etc. - Cyber security certifications like OSCP, CEH, GPEN, Pentest are highly desirable. As a Cyber Security Analyst specializing in Penetration Testing, your role involves performing security assessments for applications, infrastructure, and emerging technologies. You will guide product/service teams in secure design and implementation of IT systems. Your key responsibilities will include: - Performing penetration tests for high-risk Enterprise IT assets. - Gaining an understanding of the business process application architecture, IT infrastructure, and interaction with external entities. - Collaborating with the PDO team to define and agree on the scope of the test. - Conducting Pen testing for web/mobile applications to verify security implementation and identify vulnerabilities. - Assessing the risk of identified vulnerabilities, proposing countermeasures, and documenting technical findings and recommendations for non-technical stakeholders. - Following security governance processes for issue tracking and closure. - Using Standard Operating Procedures (SOP) for securely conducting penetration testing studies. - Developing, testing, and maintaining custom security testing scripts for vulnerability testing. - Promoting awareness of security issues among application and business teams through training programs. - Staying up to date with the latest security trends, tools, and techniques to enhance penetration testing skills. Your skillset should include: - Experience in Penetration Testing processes and tools, with a specialization in web, mobile applications, and API services. - Knowledge of security assessment, risk management processes, cyber security threats, vulnerabilities, and attack methods. - Familiarity with industry frameworks for penetration testing like OWASP, PTES, MITRE ATT&CK, Metasploit. - Ability to understand complex information system architecture and business processes to develop attack methods. - Experience in deploying various attack methods and techniques such as DDoS, brute force, spoofing, injection attacks, etc. - Knowledge and experience in applying cryptography, computer networking concept
More at Ford Motor Company
Related open roles
PSOC Monitoring Analyst
Chennai
PSOC Monitoring Analyst
Chennai
Fiserv Security Administrator & Systems Analyst - Ford Credit Bank
Salt Lake City · Hybrid
PSOC Monitoring Analyst
Remote · Chennai
SAP Platform Security Architect
Detroit · Hybrid
SAP Security Consultant - S/4 HANA & GRC Specialist (Chennai)
Chennai