Job Openings Pentester Findings & Cyber Security Analyst

About the job Pentester Findings & Cyber Security Analyst

Just Vargas is a human resources consultancy that recruits, trains, accompanies, challenges, and encourages candidates and companies to make the best use of their talents.

We are currently looking for a Pentester Findings & Cyber Security Analyst for a reference client in the Financial Sector.

Key Responsibilities:

  • Review, analyse, and validate findings from penetration testing reports, ensuring technical accuracy, plausibility, and alignment with internal security standards;
  • Assess the severity, relevance, and reproducibility of identified vulnerabilities;
  • Request technical clarifications from penetration testers and system owners where required;
  • Evaluate and validate proposed remediation measures, ensuring they effectively address identified vulnerabilities before closure;
  • Support engineering, operations, and business stakeholders in interpreting penetration testing findings and remediation recommendations;
  • Advise engineering and operations teams on appropriate mitigation and remediation strategies;
  • Review extension requests for open penetration testing findings, assessing business justification and associated risk;
  • Collaborate closely with system owners, penetration testers, security operations teams, and risk stakeholders throughout the remediation lifecycle;
  • Provide clear, constructive feedback on remediation quality and implementation;
  • Contribute to the continuous improvement of the enterprise-wide penetration testing framework and associated governance processes;
  • Ensure penetration testing activities and remediation processes remain aligned with internal security standards and regulatory requirements, including BAIT, EBA, DORA, and TIBER-EU;
  • Help strengthen the organisation's cybersecurity posture by identifying and mitigating security vulnerabilities across the organisation and its international subsidiaries.

Requirments:

  • Minimum of 3 years' hands-on experience in penetration testing, security assessments, red teaming, application security, infrastructure security, or secure software development;
  • Strong understanding of common vulnerability classes, including the OWASP Top 10 and SANS Top 25;
  • Practical experience working within regulated financial environments and applying cybersecurity frameworks such as BAIT, EBA ICT & Security Guidelines, DORA, and TIBER-EU/TIBER-DE;
  • Proven ability to reproduce security findings and technically validate remediation measures;
  • Experience reviewing penetration testing reports and working with vulnerability management platforms and ticketing systems (e.g., JIRA);
  • Background in Information Security, Infrastructure, Software Engineering, Computer Science, or a related technical discipline;
  • Strong analytical and problem-solving skills with excellent attention to detail;
  • Excellent communication and stakeholder management skills, with the ability to engage effectively with both technical and non-technical audiences;
  • Structured, solution-oriented, and quality-focused approach to work;