Headquarters: Seattle, WA
URL: https://www.wordfence.com/
We’re looking for a Safety Analyst to work on an hourly contract foundation from your property workplace, with 100% availability throughout that point.
The next shifts can be found:
Sunday-Thursday, 3:00 AM – 11:00 AM ET (40 hrs/wk)
Tuesday-Saturday, 11:00 PM – 7:00 AM ET (40 hrs/wk)
Saturday-Sunday, 11:00 AM – 7:00 PM ET (16 hrs/wk)
Candidates in areas the place these hours strongly align with their regular enterprise hours are inspired to use. You shouldn’t have to be based mostly within the USA.
The contract fee for this function is $25-30 USD per hour, relying on expertise.
Job Description
We’re in search of Safety Analysts to affix our Care and Response Staff. You’ll help our prospects with help questions associated to our product and examine web site intrusions, in addition to restore their websites and take away all traces of compromise.
Moreover, you’ll accumulate and course of proof from intrusions that may assist enhance our risk detection. You will want to find out how the intrusion occurred, accumulate all IOCs (indicators of compromise), and work with our Risk Intelligence staff on vulnerability analysis and malware signature growth.
In your downtime, you’ll triage and validate vulnerability experiences submitted by our Bug Bounty Program. You’ll assess influence to prioritize submissions, reproduce and analyze vulnerabilities in managed environments, and determine root causes in supply code. You’ll doc findings, advocate fixes or customized firewall guidelines, and suggest bounty quantities based mostly on severity and influence.
You’ll collaborate with builders, buyer help, and disclosure groups, in addition to validate that patches are enough as soon as launched.
Common necessities:
- Extremely technical and cozy with a variety of open supply instruments equivalent to grep, discover, and so on.
- Glorious written and verbal communication expertise.
- Potential to work together with prospects professionally.
- Work nicely in a staff and work independently with out extra steering.
- Glorious analytical capability, capability to suppose exterior of the field, and an eagerness to be taught.
- Will need to have consideration to element.
The particular expertise we require for this place are:
- 3+ years of expertise with WordPress required.
- Technical expertise with widespread net utility based mostly vulnerabilities in WordPress plugins and themes.
- A stable understanding of WordPress hooks, how they’re used, and the way they’ll result in vulnerabilities.
- 5+ years of expertise administering a number of Linux stacks. (We do not help Home windows.)
- 5+ years of expertise with MySQL.
- 2+ years of expertise conducting remediation of compromised web sites, together with evaluation of how the intrusion occurred, eradicating the intrusion vector, and restoring the location to a totally useful state.
- Expertise in vulnerability analysis is a plus, which incorporates:
- Potential to develop proof of ideas programmatically or conceptually to check the exploitability of vulnerabilities, and the final capability to learn/perceive programmatic and conceptual proof of ideas.
- Potential to duplicate the exploitability of vulnerabilities in a check surroundings.
- Potential to evaluation supply code modifications to find out if a vulnerability was patched and what the patch was for.
- Expertise producing/modifying HTTP requests.
- Expertise working with BURP suite or related proxy software program and a PHP debugger.
- A stable understanding of normal expressions. Should have the ability to write expressions on the fly to match and take away solely malicious code (typically polymorphic) with out affecting any professional code and to put in writing malware signatures for our merchandise.
- Potential to put in writing and browse PHP, common expressions, cron jobs, and JavaScript.
- Understanding of all main vulnerability sorts and the flexibility to clarify them to a buyer in phrases they’ll perceive.
- Potential to research log information and decide how an intrusion occurred.
- Certifications in penetration testing or forensics are a powerful plus.
- Help different groups throughout downtime.
Hiring Course of
We evaluation all purposes submitted and reply to all candidates normally inside one to 2 weeks.
- Please fill within the type supplied on this utility. The hiring staff will have a look at this primary. The way in which you reply our type will decide in case your utility strikes to the subsequent step. Please word that we learn each reply and this kind is a essential a part of our hiring course of.
- Candidates who seem to have the suitable expertise from the preliminary utility will probably be despatched a extra detailed Evaluation Check to additional assess expertise.
- Take part in a collection of cellphone interviews. We’re respectful of your time and maintain the variety of interviews you will have to take care of a minimal. That is normally two or three interviews. All interviews are carried out remotely with no journey concerned.
- All contracts and affords of employment are contingent on the profitable completion of a background test. The outcomes of the background test are thought of as they relate to the place and don’t routinely disqualify somebody from a contract or employment with the corporate.
- All positions require a trial interval of roughly 2-3 weeks with a minimal dedication of 10 hours per week. You’ll be paid for this short-term contract, and it is going to be used to guage whether or not each events need to pursue an ongoing, common employment relationship.
Advantages
Full-time telecommuting with an organization that has been 100% distant for over 8 years.
Variety at Defiant
We worth range and don’t discriminate based mostly on race, colour, faith or creed, nationwide origin or ancestry, intercourse, age, bodily or psychological incapacity, navy or veteran standing, gender identification or expression, marital standing, sexual orientation, political ideology, financial standing, parental standing, or some other non-performance-related standing.
To use: https://weworkremotely.com/remote-jobs/defiant-inc-security-analyst-for-infected-websites-contract
Source link