Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Cyber Security Engineer (Pen Tester) image - Rise Careers
Job details

Senior Cyber Security Engineer (Pen Tester)

Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to hearing from you. Introduction NSPA are looking for engineers to support their Cyber Security infrastructure to covering day to day and project activities, in addition providing Cyber Security services to NSPA customers or partners from across the NATO nations.Day to Day Activities• Planning and carrying out the replacement of products or technologies within the infrastructure. This will involve developing time schedules, collaborating with the helpdesk, communicating with the customers, configuring the new equipment and performing the actual migration work. Following this, documentation and diagrams will have to be updated.• Operating and maintaining a wide variety of different cyber security solutions on a day-to-day basis, including but not limited to: Network firewall, web proxy, mail proxy and anti-spam, antivirus for servers, DMZ segregation, web application firewall, intrusion prevention, SIEM log correlation and reporting, managed file transfer, certificates, strong authentication etc.• Providing support on various cyber security tasks and operations, such as incident response, troubleshooting, change management, write and implement security procedures for operating security solutions, lifecycle management, security and risk assessments, etc.Project Activities• Assessment of new cyber security products or technologies. This will involve researching the product, liaising with the manufacturer, arranging for a lab trial, conducting a test phase and then writing a report and making recommendations to NSPA.• Design and implementation of new secure solutions for various projects and to ensure that NSPA Cyber Security posture remains adequate and aligned with best practices.• Operating effectiveness testing and improvement of existing cyber security controls involving various cyber security technologies (including but not limited to network firewalls, Web Application firewalls, SIEM, Network IPS, e-mail protection, web browsing protection, Public Key Infrastructure, Medium and Strong authentication, etc.).• Cyber Security advisory and support provided for various customer projects.• Cyber Security penetration testing project.Working Location• Main working location: Capellen, Luxembourg (NSPA HQ)• Some projects may require business travel to other sites• Some remote/hybrid work may be requiredWorking Hours• Monday to Thursday:• Arrival 06:00 to 09:00• Lunch break Minimum 30 minutes 11:45 – 13:45• Departure 16:15 to 20:00• Friday• Arrival 6:00 to 9:00• Departure 12:15 to 17:00• Public Holiday of Luxenberg will be applicable• Some on-call duties and weekend work will be required on a rotation basisProject Duration• 3 years + 2 YearsMandatory Requirements• Professional Experience• Proven experience of at least 5 years in IT Cyber Security.• Proven experience of at least 1 year in a NATO environment.• Proven experience and skills (Minimum 8 of the below)• Next Generation Firewalls (including Intrusion Detection/Prevention System),• Web Application Firewalls and Reverse Proxies,• Web Proxies• E-mail gateways• Vulnerability Management• Anti-malware, sandboxing and endpoint protection technologies• Public Key Infrastructures (PKIs), smartcards and user authentication technologies• Mobile Device Management (MDM)• Apple infrastructure and iOS management• Security Incident Event Management (SIEM)• Multi-Factor authentication• Privileged Access Management• Good Knowledge - Ability to troubleshoot and solve issues involving the aforementioned technologies• Skills• Good Knowledge - Web application penetration testing• Good Knowledge - Mobile application penetration testing• Good Knowledge - Source code vulnerability analysis• Good Knowledge - Ability to identify and exploit web vulnerabilities (XSS, CSRF, SQLi, SSRF, arbitrary file upload, etc.)• Good Knowledge - Ability to identify and exploit mobile vulnerabilities (API issues, insecure storage, memory corruption, deep links, etc.)• Good Knowledge - Network penetration testing experience• Good Knowledge - Protocol analysis• Good Knowledge - CTF experience• Good Knowledge - Secure coding practices• Good Knowledge - Cryptography• Good Knowledge - Red and Blue team experience• Proven knowledge of• Good Knowledge - Cloud Architecture and Security• Good Knowledge - Operating System (Windows and Linux) security and of Active Directory security• Good Knowledge - Networking protocols• Good Knowledge - Application Security• Experience allowing to write scripts efficiently - Programming Skills in Bash or Python or Perl• Good Knowledge - Offensive security tactics, techniques, tools and procedures• Triage, following, procedures pro-active pivoting and hunting - Handling security alerts (ex: antivirus alert, suspicious email report)• Good Knowledge - Handling security incident/intrusion• Language• Proficiency in English, written and oral, equivalent to CEFR B2 or higher• Ability to write clear and concise reports and technical documentation with proper justification• Ability to explain issues at different levels of the hierarchy and in particular to management• Security Clearance• Hold a valid NATO SECRET (or higher) security clearanceWe never know what new opportunities might be just over the horizon. If this opportunity isn't for you please feel free to send us your resume anyway and be the first to know if something suitable for your skills and experience comes up.
Spektrum Glassdoor Company Review
4.5 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Spektrum DE&I Review
4.7 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Spektrum
Spektrum CEO photo
Unknown name
Approve of CEO

Average salary estimate

$110000 / YEARLY (est.)
min
max
$90000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Cyber Security Engineer (Pen Tester), Spektrum

Are you ready to take your skills to the next level as a Senior Cyber Security Engineer (Pen Tester) with Spektrum? We’re on the lookout for passionate professionals to join our dedicated team supporting NSPA's Cyber Security infrastructure. In this exciting role, you'll be deeply involved in day-to-day operations, from planning and implementing technology migrations to maintaining a wide spectrum of security solutions including network firewalls and intrusion detection systems. Your expertise will be critical in incident response procedures and in crafting secure solutions tailored to various projects. If you’re adept at performing comprehensive cyber assessments and implementing cutting-edge security measures, this position could be your perfect fit! Beyond the daily operations, you’ll engage in real-world penetration testing, contributing directly to enhancing our security posture. With opportunities for hybrid work and the possibility of travel, you'll find a dynamic and supportive work environment that values innovation and expertise. You’ll enjoy structured working hours that gives you a great work-life balance while supporting operations across NATO nations. Aspiring engineers with solid cyber security foundations and at least five years of relevant experience can make a notable impact with us. If you're equipped with the right skills in security technologies and possess valid NATO security clearance, we’d love to hear from you. Join us on this exciting journey at Spektrum and help shape the future of cyber security!

Frequently Asked Questions (FAQs) for Senior Cyber Security Engineer (Pen Tester) Role at Spektrum
What are the responsibilities of the Senior Cyber Security Engineer (Pen Tester) at Spektrum?

As a Senior Cyber Security Engineer (Pen Tester) at Spektrum, your responsibilities will include planning technology migrations, operating and maintaining various security solutions, and providing support for incident response and change management. You'll also assess new products, design secure solutions for projects, and conduct penetration testing, making a significant impact on NSPA's Cyber Security infrastructure.

Join Rise to see the full answer
What qualifications do I need to apply for the Senior Cyber Security Engineer (Pen Tester) position at Spektrum?

To apply for the Senior Cyber Security Engineer (Pen Tester) position at Spektrum, you need a minimum of 5 years of experience in IT Cyber Security, with at least 1 year in a NATO environment. Familiarity with various security technologies and protocols, proven analytical skills, and the ability to write technical documentation are essential qualifications.

Join Rise to see the full answer
What skills are essential for the Senior Cyber Security Engineer (Pen Tester) role at Spektrum?

Essential skills for the Senior Cyber Security Engineer (Pen Tester) role at Spektrum include expertise in penetration testing, knowledge of intrusion detection systems, and experience with tools like SIEM and firewalls. You should also be proficient in scripting languages such as Bash or Python, understand secure coding practices, and have a good grasp of both network and application security.

Join Rise to see the full answer
Is travel required for the Senior Cyber Security Engineer (Pen Tester) position at Spektrum?

Yes, the Senior Cyber Security Engineer (Pen Tester) position at Spektrum may require occasional business travel for specific projects. This includes working at different sites and collaborating with teams across NATO nations, providing you with a variety of experiences and opportunities.

Join Rise to see the full answer
What is the working environment like for the Senior Cyber Security Engineer (Pen Tester) at Spektrum?

At Spektrum, the working environment for the Senior Cyber Security Engineer (Pen Tester) is dynamic and collaborative. You will have a structured schedule that promotes work-life balance and allows some remote/hybrid work. You’ll be part of a dedicated team, engaging with cutting-edge technologies in a supportive atmosphere where innovation is encouraged.

Join Rise to see the full answer
Common Interview Questions for Senior Cyber Security Engineer (Pen Tester)
Can you describe your experience with penetration testing?

When answering this question, share specific examples of penetration testing projects you have worked on. Highlight the tools and methodologies you used, your approach to identifying vulnerabilities, and the outcomes of your assessments. Mention any documentation you've created to support your testing process.

Join Rise to see the full answer
What is your approach to incident response?

Discuss your method for approaching incident response. Describe the steps you take when an incident is detected, including containment, eradication, and recovery. Be sure to mention your experience working with teams and your ability to communicate findings to management effectively.

Join Rise to see the full answer
How do you stay updated on the latest cyber security threats?

Explain your strategies for keeping abreast of new cyber security threats. You might reference participation in industry conferences, following relevant publications, engaging in online forums, or perhaps using threat intelligence tools. Show your commitment to continuous learning in the field.

Join Rise to see the full answer
What security technologies have you implemented in your previous roles?

Provide details about security technologies you've implemented. Be specific — talk about firewalls, SIEM, intrusion detection systems, or any other technologies relevant to the position. Highlight your role in the implementation process and the impact on the organization’s security posture.

Join Rise to see the full answer
Can you explain the importance of secure coding practices?

When discussing secure coding practices, emphasize how they are fundamental to mitigating vulnerabilities in applications. Provide examples of secure coding principles, such as input validation, proper error handling, and employing libraries and tools for threat modeling, which you have integrated into your workflows.

Join Rise to see the full answer
How have you contributed to enhancing an organization's security posture?

Discuss specific initiatives or projects where you played a role in improving an organization’s security posture. Explain your thought processes when assessing security risks, introducing new technologies, or conducting trainings and how your contributions directly benefited the organization's overall security.

Join Rise to see the full answer
What methods do you use to evaluate the effectiveness of security controls?

Talk about methodologies you've employed to evaluate security controls, such as regular audits, penetration tests, and vulnerability assessments. Discuss how you analyze and report the results, and how you suggest improvements based on this evaluation.

Join Rise to see the full answer
How would you describe the difference between red team and blue team roles?

Discuss the roles clearly — red teams simulate attacks to identify weaknesses while blue teams defend against those attacks. Share experiences from either side, showcasing how understanding both perspectives enhances your capabilities as a Senior Cyber Security Engineer.

Join Rise to see the full answer
What challenges have you faced in previous cyber security roles?

Share specific challenges and how you addressed them, whether it was during an incident response, an upgrade of security systems, or navigating compliance requirements. Highlight your problem-solving skills and your ability to adapt and stay resilient in dynamic situations.

Join Rise to see the full answer
What are your thoughts on the importance of data encryption?

Discuss the significance of data encryption in protecting sensitive information. Share types of encryption protocols you've implemented or used, the impact of data breaches that could have been prevented through encryption, and your overall philosophy regarding data security.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Capital.Com Remote Warsaw, Mazowieckie, Poland
Posted 14 days ago
Photo of the Rise User
Posted 7 days ago
Mission Driven
Inclusive & Diverse
Take Risks
Collaboration over Competition
Growth & Learning
Photo of the Rise User
Posted 8 days ago
Dental Insurance
Flexible Spending Account (FSA)
Vision Insurance
Paid Holidays
Photo of the Rise User
Posted 3 days ago
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
December 9, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!