Cybersecurity Consultant
Mariner innovates always and everywhere, turning novel ideas into practical solutions. From products and services to venture creation, we build better futures powered by people. Our purpose has always been to be a great, everlasting technology company for those who make an impact – elevating people, data, and technology in the best way to solve hard problems. We partner with people embracing change, leveraging data, cybersecurity, cloud, and change management to drive successful business outcomes that matter to our customers.
Mariners build for change. Like SHIFT Energy, our energy management and decarbonization company. Or East Valley created to scale social economic impact in our communities through investment and mentorship of emerging change-makers and their companies.
Mariner’s purpose has always been to be a great, everlasting technology company and the core values that guide us every day are:
OUR VALUES
- We care for our team.
- We care about the impact we have on our community.
- We serve by solving complex problems.
- We grow because growth fuels opportunities.
- We innovate always and everywhere.
- We build a business that lasts.
OVERVIEW OF THE ROLE:
As a Security Consultant – VAPT, you will be responsible for conducting security assessments, vulnerability scans, and penetration tests to identify potential security risks. You will work closely with clients to evaluate their security posture, provide detailed reports on findings, and recommend remediation strategies to enhance overall security resilience.
KEY RESPONSIBILITIES:
- Conduct security assessments, including external and internal penetration testing, web and mobile application security testing, and network infrastructure testing.
- Perform vulnerability scanning, exploit analysis, and risk assessments using industry-standard tools.
- Simulate real-world cyber-attacks to identify security weaknesses and assess potential impacts.
- Develop and execute test cases to assess security controls and system resilience.
- Analyze vulnerabilities and threats to determine risk levels and potential business impacts.
- Prepare detailed security assessment reports, outlining findings, risk ratings, and remediation recommendations.
- Communicate technical security issues and remediation plans to both technical teams and non-technical stakeholders.
- Provide recommendations to strengthen security defenses based on testing results.
- Collaborate with development, IT, and security teams to implement remediation strategies.
- Stay updated with the latest threats, vulnerabilities, and attack methodologies to enhance assessment techniques.
- Ensure security assessments align with industry standards and frameworks (e.g., OWASP, NIST, ISO 27001, PCI DSS).
- Assist clients in meeting compliance requirements through security testing and risk mitigation strategies.
- Utilize and maintain security testing tools such as Burp Suite, Metasploit, Nessus, Nmap, Kali Linux, and others.
- Develop custom scripts and tools to automate security assessments where applicable.
- Engage with clients to understand security requirements and tailor VAPT assessments accordingly.
QUALIFICATION AND SKILLS:
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
- Industry-recognized certifications such as OSCP, CEH, PNPT, GPEN, or CISSP are highly desirable.
- 4+ years of hands-on experience in vulnerability assessments and penetration testing.
- Strong knowledge of security assessment methodologies, frameworks (e.g., OWASP Top 10, SANS 25), and attack techniques.
- Hands-on experience with security testing tools such as Burp Suite, Metasploit, Nessus, Qualys, Nmap, and Wireshark.
- Experience in testing web applications, APIs, mobile apps, network infrastructure, and cloud environments.
- Knowledge of scripting and automation using Python, PowerShell, or Bash.
- Strong analytical, problem-solving, and report-writing skills.
- Excellent communication and client engagement skills.
PREFFERED EXPERIENCE:
- Familiarity with cloud security assessments (AWS, Azure, GCP).
- Knowledge of Secure SDLC (DevSecOps) and code review techniques.
- Experince working in public sector.
…AND YOU ARE…
- Always improving your skills and knowledge: you want to be the best at what you do
- Curious and creative; comfortable taking on new problems and challenges
- A self-starter with the ability to recommend priorities to the project leader
- Comfortable working through problems and figuring things out with minimal supervision
- Great problem-solving skills: thorough and reliable
- Able to work in a team: share knowledge and assist other team members
- A good communicator: able to explain your ideas and recommendations
- Well organized and dependable under pressure: you manage your time effectively
- Energized by our company values!