Business Analyst
Detailed description of VM-platform functionality and attack vectors via Use Cases (actors, preconditions, main scenario, alternative scenarios, postconditions, exception/error handling); Identification of user problems (pain points) of systems (IS specialists, implementation, etc.) and their translation into business requirements and functional product requirements; Description (at conceptual and logical levels) of what the product should do: how the user should see the attack graph, how vulnerability filtering should occur, what steps an IS specialist should take from breach detection to issuing a patching task (Remediation Workflow); Development of interface concepts, interactive dashboards, attack vector matrices, and reports. Description of the behavior logic of interface elements under various IS specialist action scenarios; Defense of designed Use Cases before the System Analyst (SA) for subsequent design of technical contracts (API, DB) and architecture. Backlog prioritization together with the Head of Department; Development of requirements for algorithms for constructing attack graphs (Attack Path Analysis). Designing the logic by which the system should link client network topology, access rights, and found vulnerabilities into potential compromise chains.
Requirements
Higher education in the field of information security; At least 6 years of experience in the role of system/business analyst in IS, or IS architect; Knowledge of methodologies and vulnerability databases (OWASP Top 10 for Web/API, CWE, CAPEC, CVE); Understanding of the MITRE ATT&CK framework for classifying attack scenarios; Knowledge of the CTEM methodology; Knowledge of the regulatory and legal framework for IS (GOST/ISO, regulator requirements) and the ability to quickly adapt their requirements to product functionality; Understanding of the principles of security analysis and vulnerability searching in IT infrastructure; Understanding of modern OS architecture (Windows, Linux) and network protocols; Technical English at the level of independent documentation reading; Developed communication skills, the ability to translate the "pains" of IS engineers into formalized requirements for developers and defend solutions before architects; Constant professional development and monitoring of news in the field of information security; Readiness for business trips. Experience working with VM, BAS class products, or graphical attack path analysis tools (BloodHound); Experience in modeling complex and combined attack vectors (Abuse Cases, Misuse Cases, Attack Chains / Kill Chain, working with attack graphs); Experience in network equipment administration (understanding firewall rules, network segmentation, VLAN); Possession of specialized certificates in the field of IS.
Higher education — specialist degree, master's degree; Experience: 6 years