Can you imagine a world where business and digital solutions will be truly seamless and where users will help companies to co-create them?
Do you want to help us to shape this human-centered world? Welcome to UNGUESS.
UNGUESS is the crowdsourcing platform for effective testing and real insights that enable tech, digital and business leaders to make smarter decisions, faster.
How? Unleashing the power of the crowd, a community of highly engaged people all over the world that allows us to bring end-customer insights into the design, development, and testing phases of a product.
We are looking for a Cyber Security Specialist, who will take ownership of our bug bounty programs as a triager and ensure that they are managed at best: on time, with professionalism and to a high standard.
Moreover, this role will assist in cyber security activities such as penetration testing and code reviews alongside the cyber security expert.
Requirements:
Strong understanding of common vulnerabilities (OWASP Top 10, etc.) and corresponding mitigation strategies
Proven experience in penetration testing and ethical hacking
Familiarity with bug bounty programs and external collaboration with security researchers
Good technical skills with a keen interest in learning methodologies and exploit techniques
Excellent communication and interpersonal skills, with an ability to engage people at all levels of the organization
Spoken and written Italian and English at proficient level
Critical thinking and problem-solving skills
Strong attention to detail
Bachelor's / Master's degree in Computer Science, Information Security, or a related field is a plus
Certifications such as OSCP, OSCE, CISSP, or equivalent are a plus
An excellent team player
Enthusiasm to be part of a fast-growing startup on a mission to make the world more human-centered
Ability to work independently and collaboratively in a team environment
Solution-oriented, constantly looking for ways to make things work better, run smoother and take less time
Able to showcase proactive tendencies, continuously looking for ways to add and create value
Responsibilities:
Manage and monitor the organization's bug bounty program, ensuring timely triage and resolution of reported vulnerabilities
Conduct comprehensive penetration tests on web applications, networks, and infrastructure to identify and exploit vulnerabilities
Provide mentorship and training to internal teams on secure coding practices and general security awareness
Collaborate with cross-functional teams to validate and verify reported vulnerabilities, ensuring accurate assessments
Proactively monitor financial information of projects to ensure a healthy project margin
Create comprehensive reports for both internal and external stakeholders, summarizing identified vulnerabilities and recommended corrective actions
Proactively identify areas for improvement in security processes and methodologies
Participate in red teaming exercises and contribute to the enhancement of the organization's overall security strategy
What do we offer:
Training courses and possible certifications
Opportunity to grow in a short time period
Package: 28 - 35 K RAL to be adapted according to experience and skills, competitive package with flexibility on location and holidays policy
Location: the role is entirely remote
Part time at present with the intention of gradually increasing to full time
#J-18808-Ljbffr