TVM/Penetration tester Security Advisor
Internship Pomezia (Roma Capitale)
Job description
· Job Description:
As a TVMSecurity Advisor , you will be part of a specialized professional group that faces new challenges and new strategies to help clients’ businesses to improve their security posture and grow their resilience to threats.
You will be part of security digital transformation and the change of paradigm from a remediation-based approach to a prevention-based one.
DXC will give you the opportunity to earn knowledge and expertise on a wide range of innovative technologies and methodologies and to work with industry experts.
As a TVM/Penetration tester Security Advisor, you will be involved in the following activities:
· Advise customers to defend themselves against the most advanced cyber adversaries and mitigate exposure to threats targeting applications, hardware (OT/IOT) and enterprise assets.
· Perform security analysis in complex environment and assist clients during all phases of SSDLC
· Support clients to identify the existing threat actors, improve their awareness through a cyber-attack and boost up the ability to detect, prevent, and respond to infrastructure threats (networks, clouds, endpoints, mobile and IoT).
The ideal candidate for this position has:
· Specialized degree in technical / scientific subjects (Engineering, Computer Science, Mathematics, Physics, Statistics) or equivalent experience;
· At least 3 years experience preferably in consultancy companies (IT / Cyber Security sector);
· Good communication and relationship skills and focus on the customer;
· Teaming predisposition;
· Knowledge of the written and spoken English language;
· Solid skills acquired in Application Security, with particular reference in some or all of the following skills:
· Ethical Hacking or Penetration Testing (Web, Mobile, Infrastructure, OT, IOT)
· Red & Blue Teaming, Adversary Simulation
· SSDLC (Phases of Requirements, Design, Coding, Testing, Deployment)
· Compliance Management (OWASP, NIST, MITRE, CVE)
· Vulnerability management
· Knowledge of Risk Management principles is appreciated
· Familiarity with Source code analysis
· Experience in Security Reporting
· Knowledge of DevSecOps methodology is appreciated
Possession of at least one certification in the field of information security / IT:
· CISSP (is appreciated), OSCP, OSCE (is appreciated), SANS GPEN, SANS GWAPT, SANS GIAC (is appreciated), CEH, GICSP (is appreciated)