Threat Identification & Prioritization

I'm looking for a Cyber Security Consultant with a solid understanding of vulnerability management and general cybersecurity concepts. The ideal candidate should possess practical knowledge of vulnerability assessment processes, common security terminology, and basic IT infrastructure components.

 

Cyber Security Fundamentals

  • Understanding of cybersecurity principles and common threat landscape.
  • Ability to explain what a security vulnerability is and understand its business and technical impact.
  • Familiarity with vulnerability severity classification and prioritization methodologies.
  • Knowledge of CVSS (Common Vulnerability Scoring System) and how vulnerability scores are used for risk assessment.
  • Understanding of vulnerability remediation processes and risk reduction practices.

Vulnerability Management

  • Experience with vulnerability scanning and assessment tools such as Qualys, Tenable Nessus, Rapid7, OpenVAS, or similar solutions.
  • Understanding of how vulnerability scanners work, their capabilities, limitations, and typical use cases.
  • Ability to identify, investigate, and research vulnerabilities using public sources such as CVE databases, NVD, vendor advisories, and security bulletins.
  • Knowledge of vulnerability prioritization based on severity, exploitability, asset criticality, and business impact.

AI Security Awareness

  • Basic understanding of security risks associated with AI systems, AI agents, Large Language Models (LLMs), and AI-enabled applications.
  • Awareness of AI-related vulnerabilities, including prompt injection, data leakage, excessive permissions, insecure integrations, and risks associated with autonomous AI agents.

Networking Fundamentals

  • General understanding of computer networking concepts, including TCP/IP, DNS, DHCP, routing, firewalls, proxies, and network segmentation.
  • Ability to troubleshoot basic network connectivity and communication issues.

Operating Systems

  • Good understanding of Microsoft Windows and Linux operating systems.
  • Familiarity with system administration fundamentals and security best practices.
  • Ability to navigate and perform basic administrative tasks on both platforms.

Command Line Skills

  • Knowledge of common Linux commands (e.g., grep, find, ps, netstat/ss, chmod, chown, journalctl, systemctl).
  • Basic PowerShell knowledge, including execution of administrative and information-gathering commands.
  • Ability to analyze logs and collect basic troubleshooting information from operating systems.
Understanding of cybersecurity principles and common threat landscape.
Ability to explain what a security vulnerability is and understand its business and technical impact.
Familiarity with vulnerability severity classification and prioritization methodologies.
Knowledge of CVSS (Common Vulnerability Scoring System) and how vulnerability scores are used for risk assessment.
Understanding of vulnerability remediation processes and risk reduction practices.
Experience with vulnerability scanning and assessment tools such as Qualys, Tenable Nessus, Rapid7, OpenVAS, or similar solutions.
Understanding of how vulnerability scanners work, their capabilities, limitations, and typical use cases.
Ability to identify, investigate, and research vulnerabilities using public sources such as CVE databases, NVD, vendor advisories, and security bulletins.
Knowledge of vulnerability prioritization based on severity, exploitability, asset criticality, and business impact.
Good understanding of Microsoft Windows and Linux operating systems.
Knowledge of common Linux commands (e.g., grep, find, ps, netstat/ss, chmod, chown, journalctl, systemctl).
Basic PowerShell knowledge, including execution of administrative and information-gathering commands.
Ability to analyze logs and collect basic troubleshooting information from operating systems.
 
Experience working in security operations, vulnerability management, risk management, or infrastructure support teams.
Familiarity with security frameworks and standards such as NIST, CIS Controls, ISO 27001, or OWASP.
Security certifications such as CompTIA Security+, CompTIA CySA+, SC-900, AZ-500, or similar.
ID: 4069 job_post.published_on: 07/10/2026
announcement.apply