What are the responsibilities and job description for the IT Security Analyst position at Aramco?
Aramco Services Company
IT Security Analyst (1440)
Governance Risk & Compliance - Houston, TX – Full-Time
POSITION OVERVIEW :
The IT Security Analyst II position applies mid-level principles and moderate to highly complex research, evaluation, managing, administering, auditing, and testing company IT systems to manage risk. The Penetration Tester position focuses on offensive security tasks such as penetration testing, vulnerability assessments, and red teaming exercises. The role involves identifying and exploiting security weaknesses in systems, networks, and web applications to simulate real-world attacks and test the organization's defenses. The goal is to improve the overall security posture by providing actionable insights and recommendations
The incumbent is generally well-qualified in penetration testing and red teaming, with expertise in identifying and exploiting security weaknesses. While higher-classified systems analysts can consult on work assignments, the incumbent primarily focuses on offensive security tasks. This position involves conducting penetration tests, vulnerability assessments, application code scanning, and red teaming exercises to simulate real-world attacks and test the organization's defenses.
PRINCIPAL DUTIES :
- Conduct comprehensive penetration tests on various IT systems, networks, and applications to identify vulnerabilities and security weaknesses.
- Perform red teaming exercises to simulate advanced persistent threats (APTs) and assess the organization's detection and response capabilities.
- Develop and execute attack scenarios to test the effectiveness of security controls and incident response procedures.
- Utilize advanced tools and techniques to exploit vulnerabilities and gain unauthorized access to systems and data.
- Collaborate with the blue team (defensive security) to provide insights and recommendations for improving security measures.
- Investigate suspected attacks, such as man-in-the-middle attacks, sniffing, DoS, etc., hacking activities, and breaches of Information security policies.
- Analyze security events generated by various network and host-based security appliances, such as firewalls, NIDS, HIDS, and event logs. Determine appropriate remediation actions and escalation paths to address identified security issues.
- Document findings, create detailed reports, and present results to stakeholders, including technical and non-technical audiences.
- Develop, maintain, and update process and standard governing documents related to penetration testing and red teaming activities
- Stay updated with the latest security trends, vulnerabilities, and attack techniques to ensure the organization remains resilient against emerging threats.
- Other duties as assigned.
MINIMUM REQUIREMENTS :
NO THIRD PARTY CANDIDATES ACCEPTED