Job Posting Organization: The European Bank for Reconstruction and Development (EBRD) is a pioneering international organization established in 199
The EBRD's mission is to foster the transition towards open market-oriented economies and promote private and entrepreneurial initiatives in countries across Europe, Asia, and the Middle East. The bank operates in over 30 countries and employs a diverse workforce of approximately 2,000 employees. The EBRD is committed to sustainable development and aims to support the growth of the private sector in its regions of operation, ensuring that investments are environmentally sound and socially responsible.
Job Overview: The Midlevel security" style="border-bottom: 1px dotted #007bff !important;">Security Engineer position at EBRD is designed for a cyber expert who is passionate about offensive security and proactive defense strategies. This role involves leading offensive security operations, which include scanning systems for vulnerabilities, probing for weaknesses, and simulating real-world attacks using standard offensive tools. The successful candidate will validate vulnerabilities through hands-on exploitation and craft custom scripts to expose hidden threats. The position requires a deep technical expertise and a hacker mindset, with fluency in web technologies and a solid understanding of the OWASP Top 10 vulnerabilities. The engineer will also engage in threat intelligence activities, develop hypotheses, and contribute to smarter detection strategies, ultimately influencing real-world defense strategies and enhancing the organization's security posture.
Duties and Responsibilities: The duties and responsibilities of the Midlevel Security Engineer include planning, developing, and executing vulnerability scans of the organization's information systems. The engineer will identify and resolve false positive findings in assessment results and perform reconnaissance and information collection on the target environment or attack surface. They will identify potential weaknesses and vulnerabilities on assets, including endpoints, applications, and users, and validate these weaknesses through exploitation, reporting their findings accordingly. The engineer will recommend security controls and corrective actions to mitigate technical and business risks, create hypotheses for analytics and testing of threat data, analyze data from threat and vulnerability feeds, and generate reports on assessment findings to facilitate remediation tasks. Additionally, they will share lessons learned and initial indicators of detection to strengthen signature-based detection capabilities.
Required Qualifications: Candidates must possess the highest level of technical expertise in cybersecurity, with a deep familiarity with penetration and intrusion techniques and attack vectors. A strong understanding of web technologies and core security fundamentals is essential. Familiarity with the OWASP Top 10 vulnerabilities is required, along with knowledge of offensive tools such as Metasploit, Kali Linux, Cobalt Strike, and Mimikatz. Proficiency in creating scripts and regular expressions in a preferred scripting language is necessary. Technical knowledge in system security vulnerabilities, remediation techniques, network and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP), and security engineering is also required. While not essential, certifications such as Certified Ethical Hacker (CEH), Global Information Assurance Certification (GIAC), GIAC Certified Pen Tester (GPEN), GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), Offensive Certified Security Professional (OSCP), and Offensive Security Certified (OSC) are desired.
Educational Background: The educational background required for this position includes a degree in Computer Science, Information Technology, Cybersecurity, or a related field. Advanced degrees or specialized training in cybersecurity or information security are advantageous and may enhance a candidate's profile.
Experience: Candidates should have a minimum of 3-5 years of experience in cybersecurity, specifically in offensive security roles. Experience in vulnerability assessment, penetration testing, and threat intelligence is crucial. Familiarity with security frameworks and standards, as well as hands-on experience with security tools and technologies, is expected.
Languages: Fluency in English is mandatory, as it is the working language of the EBRD. Knowledge of additional languages, particularly those relevant to the EBRD's regions of operation, is considered a plus and may enhance a candidate's application.
Additional Notes: This position is a fixed-term contract lasting for 3 years. The EBRD promotes a hybrid working culture, encouraging collaboration in person at least three days a week. The organization values diversity and inclusion, ensuring equal opportunities for all candidates regardless of their background. The EBRD offers a comprehensive suite of competitive benefits and prioritizes employee wellbeing.
Info
Job Posting Disclaimer
This job posting is provided for informational purposes only. The accuracy of the job description, qualifications, and other details mentioned is the sole responsibility of the employer or the organization listing the job. We do not guarantee the validity or legitimacy of this job posting. Candidates are advised to conduct their own due diligence and verify the details directly with the employer before applying.
We are not liable for any decisions or actions taken by applicants in response to this job listing. By applying, you agree that all application processes, interviews, and potential job offers are managed exclusively by the listed employer or organization.
Beware of fraudulent job offers. Do not provide sensitive personal information or make any payments to secure a job.