Job Openings
Pentester Findings & Cyber Security Analyst
About the job Pentester Findings & Cyber Security Analyst
Just Vargas is a human resources consultancy that recruits, trains, accompanies, challenges, and encourages candidates and companies to make the best use of their talents.
We are currently looking for a Pentester Findings & Cyber Security Analyst for a reference client in the Financial Sector.
Key Responsibilities:
- Review, analyse, and validate findings from penetration testing reports, ensuring technical accuracy, plausibility, and alignment with internal security standards;
- Assess the severity, relevance, and reproducibility of identified vulnerabilities;
- Request technical clarifications from penetration testers and system owners where required;
- Evaluate and validate proposed remediation measures, ensuring they effectively address identified vulnerabilities before closure;
- Support engineering, operations, and business stakeholders in interpreting penetration testing findings and remediation recommendations;
- Advise engineering and operations teams on appropriate mitigation and remediation strategies;
- Review extension requests for open penetration testing findings, assessing business justification and associated risk;
- Collaborate closely with system owners, penetration testers, security operations teams, and risk stakeholders throughout the remediation lifecycle;
- Provide clear, constructive feedback on remediation quality and implementation;
- Contribute to the continuous improvement of the enterprise-wide penetration testing framework and associated governance processes;
- Ensure penetration testing activities and remediation processes remain aligned with internal security standards and regulatory requirements, including BAIT, EBA, DORA, and TIBER-EU;
- Help strengthen the organisation's cybersecurity posture by identifying and mitigating security vulnerabilities across the organisation and its international subsidiaries.
Requirments:
- Minimum of 3 years' hands-on experience in penetration testing, security assessments, red teaming, application security, infrastructure security, or secure software development;
- Strong understanding of common vulnerability classes, including the OWASP Top 10 and SANS Top 25;
- Practical experience working within regulated financial environments and applying cybersecurity frameworks such as BAIT, EBA ICT & Security Guidelines, DORA, and TIBER-EU/TIBER-DE;
- Proven ability to reproduce security findings and technically validate remediation measures;
- Experience reviewing penetration testing reports and working with vulnerability management platforms and ticketing systems (e.g., JIRA);
- Background in Information Security, Infrastructure, Software Engineering, Computer Science, or a related technical discipline;
- Strong analytical and problem-solving skills with excellent attention to detail;
- Excellent communication and stakeholder management skills, with the ability to engage effectively with both technical and non-technical audiences;
- Structured, solution-oriented, and quality-focused approach to work;