Security Analyst for Infected Websites
3 settimane fa
We're seeking a Security Analyst to work on an hourly contract basis from your home office, with 100% availability during that time. The following shifts are available: Weekdays: Monday-Friday, 9:00 AM - 5:00 PM ET (40 hrs/wk) Weekends: Saturday-Sunday, 11:00 AM - 7:00 PM ET (16 hrs/wk) Candidates in regions where these hours strongly align with their normal business hours are encouraged to apply. You do not have to be based in the USA. The contract rate for this role is $35+ USD per hour, depending on experience. Job Description We are looking for Security Analysts to join our Care and Response Team. You will assist our customers and investigate site intrusions, as well as repair their sites and remove all traces of compromise. Additionally, you will collect and process evidence from intrusions that will help improve our threat detection. You will need to determine how the intrusion occurred, collect all IOCs (indicators of compromise), and work with our Threat Intelligence team on vulnerability research and malware signature development. In your downtime, you will triage and validate vulnerability reports submitted through our Bug Bounty Program. You’ll assess impact to prioritize submissions, reproduce and analyze vulnerabilities in controlled environments, and identify root causes in source code. You will document findings, recommend fixes or custom firewall rules, and propose bounty amounts based on severity and impact. You will collaborate with developers, customer support, and disclosure teams, as well as validate that patches are sufficient once released. General requirements: Highly technical and comfortable with a wide range of open source tools such as grep, find, etc Excellent written and verbal communication skills. Ability to interact with customers professionally. Work well in a team and work independently without additional guidance. Excellent analytical ability, ability to think outside of the box, and an eagerness to learn. Must have attention to detail. The specific skills we require for this position are: 3+ years of experience with WordPress required. Technical experience with common web application based vulnerabilities in WordPress plugins and themes. A solid understanding of WordPress hooks, how they are used, and how they can lead to vulnerabilities. Experience with administering multiple Linux stacks. (We don’t support Windows.) Experience with MySQL. 2+ years of experience conducting remediation of compromised websites, including analysis of how the intrusion occurred, removing the intrusion vector, and restoring the site to a fully functional state. Experience in vulnerability research is a plus, which includes: Ability to develop proof of concepts programmatically or conceptually to test the exploitability of vulnerabilities, and the general ability to read/understand programmatic and conceptual proof of concepts. Ability to replicate the exploitability of vulnerabilities in a test environment. Ability to review source code changes to determine if a vulnerability was patched and what the patch was for. Experience generating/modifying HTTP requests. Experience working with BURP suite or similar proxy software and a PHP debugger. A solid understanding of regular expressions. Must be able to write expressions on the fly to match and remove only malicious code (often polymorphic) without affecting any legitimate code and to write malware signatures for our products. Ability to write and read PHP, regular expressions, cron jobs, and JavaScript.Understanding of all major vulnerability types and the ability to explain them to a customer in terms they can understand. Ability to analyze log files and determine how an intrusion occurred. Certifications in penetration testing or forensics are a strong plus. Assist other teams during downtime. Hiring Process We review all applications submitted and respond to all candidates usually within one to two weeks. Please fill in the form provided in this application. The hiring team will look at this first. The way you answer our form will determine if your application moves to the next step. Please note that we read every answer and this form is a critical part of our hiring process. Candidates who appear to have the right skills from the initial application will be sent a more detailed Assessment Test to further assess skills. Candidates who successfully pass the Assessment Test will be invited to participate in a series of phone interviews. We are respectful of your time and keep the number of interviews you will need to attend to a minimum. This is usually two or three interviews. All interviews are done remotely with no travel involved. All contracts and offers of employment are contingent on the successful completion of a background check. The results of the background check are considered as they relate to the position and do not automatically disqualify someone from a contract or employment with the company. All positions require a trial period of approximately 2-3 weeks with a minimum commitment of 10 hours per week. You will be paid for this short-term contract, and it will be used to evaluate whether both parties want to pursue an ongoing, regular employment relationship. Benefits Full-time telecommuting with a company that has been 100% remote for over 8 years. Diversity at Defiant We value diversity and do not discriminate based on race, color, religion or creed, national origin or ancestry, sex, age, physical or mental disability, military or veteran status, gender identity or expression, marital status, sexual orientation, political ideology, economic status, parental status, or any other non-performance-related status. #J-18808-Ljbffr
-
Remote Security Analyst for Compromised WordPress Sites
2 settimane fa
Italia Remotely A tempo pienoA global technology company is looking for a Security Analyst to assist in investigating site intrusions and deploying fixes. You'll work in a fully remote environment while analyzing vulnerabilities in WordPress and securing web applications. Candidates must have at least 3 years of experience and familiarity with open source security tools. Offering...
-
Cyber Security Analyst
6 giorni fa
Italia Reply A tempo pieno 30.000 € - 60.000 € all'anoWelcome to Reply, the digital consulting company.This job is about a Cyber Security Analyst.WHAT WE OFFERCyber Security. You will join the Blue Team of our Security Operation Center and raise the security level of our national and international customers. The monitored perimeters include all the most sophisticated and recent technologies in the IT/OT and IoT...
-
Information Security Analyst
2 settimane fa
Italia Allianz A tempo pieno 60.000 € - 1.000.000 € all'anoAllianz is the home for those who dare – a supportive place where you can take the initiative to grow and to actively strengthen our global leadership position. By truly caring about people – both its 83 million private and corporate customers and its 142,000 employees – Allianz fosters a culture where its employees are empowered to collaborate,...
-
Information Security
6 giorni fa
Italia IMD business school for management and leadership courses A tempo pieno 60.000 € - 120.000 € all'anoAbout IMDThe International Institute for Management Development (IMD) has been pioneering leadership development for nearly 80 years. Founded by business for business, we are an independent university institute with Swiss roots and global reach. Operating from Lausanne with strategic hubs in Singapore, Shenzhen, and Cape Town, IMD works with 19,000+...
-
Cybersecurity Analyst
6 giorni fa
Italia Eurogarages Group A tempo pieno 30.000 € - 42.000 € all'anoRole: Cybersecurity AnalystLocation: Blackburn, BB1 2FA (Relocating to Bolton)Contract: Full-Time / Permanent / Office BasedSalary: £30,000 - £40,000 (Dependant on experience)Company: EG Group*This is an office-based role 5 days a week*About the Role:At EG Group, we're on the lookout for a sharp, driven Cybersecurity Analyst to help us stay one step...
-
Cyber Security Analyst
6 giorni fa
Italia Reply A tempo pieno 40.000 € - 60.000 € all'anoTi piacerebbe diventare un esperto di Cybersecurity e far parte di un team che affronta ogni giorno nuove sfide rilevando ed analizzando reali tentativi di attacchi cyber?Allora potresti dedicare qualche secondo alla lettura del nostro annuncio Cosa imparerai lavorando con noi?Siamo alla ricerca di un Cyber Security Analyst da inserire nel Blue Team del...
-
Cloud ASM Analyst
6 giorni fa
Italia Allianz A tempo pieno 60.000 € - 120.000 € all'anoAbout the Job Are you an experienced cloud security professional ready to take on a senior role in safeguarding a global organization from cyber threats? Join the Allianz Cyber Defense Center as a Senior Cloud Attack Surface Management Analyst and play a crucial role in securing our AWS and Azure environments. In this senior-level role, you will take the...
-
Senior NIST Analyst
2 settimane fa
Italia Allianz A tempo pieno 60.000 € - 85.000 € all'anoRole DescriptionAs a Senior NIST Analyst at Allianz UK, you will be instrumental in executing the company's Information Security strategies and initiatives, focusing on supporting the Governance, Risk, and Compliance (GRC) function and responsible for the support, maintenance, and improvement of the organization against the NIST Cyber Security Framework...
-
Security Engineer
6 giorni fa
Italia Domyn A tempo pieno 60.000 € - 100.000 € all'anoWe are seeking an experienced Security Engineer to join our Architecture & Security team. The ideal candidate will have at least 3-5 years of experience in this field and will play a crucial role in developing and maintaining our security standards, and best practices on cloud architectures. You will work closely with our development and DevOps teams to...
-
Cybersecurity SOC Analyst
2 settimane fa
Italia Cittadini dell'Ordine S.p.a A tempo pieno**A.N.I.V.P. cerca CyberSecurity SOC Analyst** **Chi siamo** A.N.I.V.P. ricerca una figura di Cybersecurity SOC Analyst, per conto di azienda associata specializzata nella sicurezza informatica, con sede a Cesena, fondata e composta da professionisti appassionati del settore, con alle spalle un percorso attivo nei principali gruppi di hacking locali. **Il...