Logo of Huzzle

Security Analyst

image

EY

6d ago

  • Job
    Full-time
    Mid & Senior Level
  • Software Engineering
    IT & Cybersecurity
  • Gurgaon
    Remote

AI generated summary

  • You should have 4-6 yrs. in app security, hands-on testing experience, knowledge of secure coding, tools like Burp and Nmap, and proficiency in languages like C#/Java; IT security certs are a plus.
  • You will conduct penetration testing, perform vulnerability assessments, prepare security reports, research application vulnerabilities, mentor team members, and support skill updates.

Requirements

  • Capable of conducting application & network penetration testing and vulnerability assessments
  • Preparing detailed security review reports and remediation guidances
  • Researching new application security vulnerabilities and attack vectors
  • Leading strategic initiatives and mentoring new team members
  • Support the team in updating their skill and knowledge
  • Hands on experience of Web, thick client, Mobile, VOIP, Wireless application security testing
  • Proficient in automated and manual application testing methodologies
  • Expert in using manual testing tools such as Burp Professional, Nmap, Wireshark, Nessus, echomirage
  • Expert in using automated application scan tool Webinspect / Qualys WAS, CheckMarx, WhiteSource etc
  • Basic Knowledge of programming language like C/C++, C#, JAVA, ASP.NET and familiar with PERL/Python Scripting
  • Familiar with OWASP and Secure SDLC standards
  • Knowledge of common security requirements within ASP.NET & Java application
  • Good Knowledge of TCP/IP, Network Security
  • Knowledge / experience on code review
  • Good Technical aptitude, problem solving and ability to quickly learn and master new topics and domains
  • Excellent communication skills; written and verbal
  • Bachelor's degree in a technical discipline such as Engineering or Computer Science or equivalent work experience in IT and Information Security
  • 4 - 6 yrs. experience in application security assessment
  • Hands on experience of Web, thick client, Mobile Application security reviews
  • Exposure and good understanding of the various manual testing methodologies
  • Desirable: IT security Certifications (CEH. ECSA, OSCP etc.)

Responsibilities

  • Capable of conducting application & network penetration testing and vulnerability assessments
  • Preparing detailed security review reports and remediation guidances
  • Researching new application security vulnerabilities and attack vectors
  • Leading strategic initiatives and mentoring new team members
  • Support the team in updating their skill and knowledge

FAQs

What is the job title for this position?

The job title is Security Analyst.

What are the key responsibilities of the Security Analyst?

The key responsibilities include conducting application vulnerability assessments and penetration testing, preparing detailed security review reports and remediation guidance, researching new application security vulnerabilities, leading strategic initiatives, and mentoring new team members.

What qualifications are required for this role?

A Bachelor's degree in a technical discipline such as Engineering or Computer Science, or equivalent work experience in IT and Information Security is required.

How much experience is needed for this position?

The role requires 4 to 6 years of experience in application security assessment.

What skills are needed for a Security Analyst at EY?

Skills required include hands-on experience in Web, thick client, and mobile application security testing, proficiency in automated and manual application testing methodologies, and knowledge of programming languages such as C/C++, C#, JAVA, and Python.

Are there any specific certifications recommended for this role?

Yes, desirable certifications include IT security certifications such as CEH, ECSA, and OSCP.

Will I have the opportunity to work in a diverse and inclusive culture?

Yes, EY promotes a diverse and inclusive culture where you will be accepted for who you are and empowered to use your voice.

What kind of support for continuous learning does EY offer?

EY offers continuous learning opportunities to develop the mindset and skills needed to navigate future challenges.

Is this role suitable for individuals interested in leading and mentoring?

Yes, the role includes responsibilities related to leading strategic initiatives and mentoring new team members.

Does the benefits package at EY focus on holistic well-being?

Yes, the EY benefits package focuses on physical, emotional, financial, and social well-being.

Accounting
Industry
1-10
Employees

Mission & Purpose

EY exists to build a better working world, helping create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. Find out more about the EY global network http://ey.com/en_gl/legal-statement