Offensive Security Sr. Analyst (mwd)
Indexed description
Our success hinges on a diversity of ideas powered by people, not egos. Whether you’re a scientist or engineer, new to the team or established, in business, production, or anything in between – we cheer each other on. Because we believe we can do anything. Explore everything. And Be Part of Something Special!
Find out more about the many benefits we offer:
https://www.evonik.com/en/careers/why.html
Meet the team and get to know the people behind Evonik:
https://www.evonik.com/en/news/meet-the-team.html
Expected Responsibilities
- Support the execution of penetration tests across web applications, enterprise infrastructure, cloud environments, and industrial systems under the guidance of senior team members.
- Assist in conducting security assessments of:
- Custom and third-party web applications.
- Enterprise applications and business-critical systems.
- Cloud-based and hybrid environments.
- Participate in vulnerability validation, attack surface analysis, and security testing activities.
- Document findings and contribute to technical reports, including:
- Vulnerability descriptions, Risk assessments. and Remediation recommendations.
- Support the presentation of assessment results to stakeholders.
- Assist in research activities related to emerging threats, attack techniques, and security tools.
- Successfully completed a university degree in (Business) Informatics, Computer Science, Cyber Security, or a comparable IT-related field — or equivalent practical experience.
- Initial experience in cyber security, basic understanding of:
- Web application security testing.
- Network and infrastructure security concepts.
- Vulnerability assessment methodologies.
- Basic understanding of Windows and Linux operating systems.
- Familiarity with networking fundamentals, including TCP/IP, DNS, HTTP/HTTPS, and Active Directory concepts.
- Basic knowledge of cloud platforms and cloud security concepts.
- Exposure to common offensive security tools
- Understanding of common web application vulnerabilities (OWASP Top 10).
- Interest in offensive security, threat emulation, and penetration testing methodologies.
- Knowledge of OT/ICS security concepts is beneficial but not required.
- Curiosity and willingness to continuously learn new technologies and attack techniques.
- Ability to work effectively both independently and as part of a team.
- Fluent English communication skills
Please address your application to the Talent Acquisition Manager, stating your earliest possible starting date and your salary expectations.
Your Talent Acquisition Manager:
Andreia Uehara
Company is
Evonik Brasil Ltda.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search