Sr. Cybersecurity Analyst
- Austin, TX, USA
Visa Technology & Operations LLC is a Visa company. Common Purpose, Uncommon Opportunity. Everyone at Visa works with one goal in mind – making sure that Visa is the best way to pay and be paid, for everyone everywhere. This is our global vision and the common purpose that unites the entire Visa team. As a global payments technology company, tech is at the heart of what we do: Our VisaNet network processes over 13,000 transactions per second for people and businesses around the world, enabling them to use digital currency instead of cash and checks. We are also global advocates for financial inclusion, working with partners around the world to help those who lack access to financial services join the global economy. Visa’s sponsorships, including the Olympics and FIFA™ World Cup, celebrate teamwork, diversity, and excellence throughout the world. If you have a passion to make a difference in the lives of people around the world, Visa offers an uncommon opportunity to build a strong, thriving career. Visa is fueled by our team of talented employees who continuously raise the bar on delivering the convenience and security of digital currency to people all over the world. Join our team and find out how Visa is everywhere you want to be.
The Sr. Information Security Analyst will work as a member of Visa Cybersecurity’s Ethical Hacking (Penetration testing) program. The objective of Visa’s Penetration Testing program is to pro-actively identify weaknesses and shortcomings in Visa’s security posture and recommend necessary controls and procedures to protect Visa adversarial threats. With this mission in mind, Visa’s pentest team experts are pro-actively involved in engagements that simulate adversarial threats and attacks in a timely manner.
The Sr. Information Security Analyst will be a key contributor for performing internal and external ethical hacks of Visa applications and systems. Pentest team members also help with design, development and recommendation of security solutions to protect Visa proprietary/confidential data and systems. The candidate will also assist with compliance objectives; provide guidance and direction for the logical protection of information systems assets to other functional units. Prepare reports regarding effectiveness of information security adherence and make recommendations for the adoption of new policies and procedures for Visa services.
• Conduct high risk and sensitive ethical hacks of internally and externally hosted applications globally according to scope defined by the pentest team.
• Subject matter expertise in web, mobile or network penetration testing with track record of end to end testing of complex systems.
• Co-ordinate and execute system/network level pentests and ethical hacking exercises.
• Pro-actively research and Identify network and system vulnerabilities and provide recommended counter measures or mitigating controls to reduce risk to an acceptable and manageable level.
• Reviews results of network and application ethical hacks in order to determine severity of findings and to ensure proper remediation is applied.
• Provide accurate and timely reporting of findings and proposed remediation and mitigations.
• Technical support could include but not limited to the following: (1) Audit support & remediation, (2) Process Improvement, (3) Analysis & Reporting, (4) Cross Divisional Functional education, training and awareness, (5) Function/Methodology/Strategy advancement.
• Provide technical support to senior management in identifying and streamlining new/existing protocols and tools used by the penetration testing team.
• Mentor junior pentesters
• Develop and automate scripts, tools and resources needed to advance ethical hacking capabilities around new and emerging technologies like mobile, cloud and embedded systems.
• Actively involved in security research around new and emerging technologies.
4 years of work experience with a Bachelor’s Degree or at least 2 years of work experience with an Advanced degree (e.g. Masters, MBA, JD, MD) or 0 years of work experience with a PhD degree
• 3-5 Years work experience in Information Security
• Master's degree (or equivalent) in Computer Science, Information Security, Information Technology, Electrical/Electronics Engineering or a related field
• Understanding of OWASP Top 10 and SANS Top 25 web application and network vulnerabilities
• Understanding of cryptographic concepts and applied cryptography (SSL, AES etc.)
• Proficiency in one or more scripting language. E.g. Perl, Python, Shell Scripting etc.
• Proficiency in one or more high level programming languages like Java, C, C++, Ruby etc.
• Expertise and experience in web/mobile application and network penetration testing
• Knowledge of exploit development, vulnerability research/reporting or writing system modules in C & C++, a major advantage and added bonus.
• Detailed understanding of OSI and TCP stack with emphasis on computer architecture and networking protocols
• Knowledge of web application technologies and layer 7 protocols like HTTP, DHCP, DNS, FTP etc.
• Good understanding of networking concepts around Ethernet, switched LAN and WAN environment
• Prior knowledge or academic familiarity with reverse engineering, malware analysis, security research and forensic tools will be an added advantage
• Familiarity with security tools & frameworks like Burpsuite, Metasploit, Kali, Canvas, etc.
• Strong problem solving and analytical skills
• Strong verbal and written communication skills
• Strong operational skills; quality and results oriented
• Strong client service orientation
· Incumbent must make themselves available during core business hours.
- This position requires the incumbent to travel for work 10% of the time.
· This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers, reach with hands and arms, and bend or lift up to 25 pounds.
If interested in the position, please reference job number REF20748K when applying through Visa Technology & Operations LLC’s inhouse media requisition posting, via SmartRecruiters.