Develops techniques and tools to analyse and expose vulnerabilities designing new vulnerability discovery techniques.
SFIA Skills: Vulnerability research (VURE)
Research activities (VURE)(Level Six)
Plans and leads the organisation’s approach for vulnerability research. Identifies new and emerging threats and vulnerabilities.
Reporting (VURE)(Level Six)
Engages with, and influences, relevant stakeholders to communicate results of research and the required response.
Networking and communities (VURE)(Level Six)
Maintains a strong external network. Takes a leading part in external-facing professional activities to facilitate information gathering.
Body of knowledge (VURE)(Level Six)
Takes a leading role in the development of the security vulnerability research body of knowledge. Initiates frequent communications with peers in other organisations and in other countries, presents keynote papers at conferences, writes for high impact journals and major clients.
Tools and techniques (VURE)(Level Five)
Adopts and adapts vulnerability assessment techniques and tools to be used by others.
Research activities (VURE)(Level Five)
Plans and manages vulnerability research activities into new threats, attack vectors, risks and potential solutions.
Reporting (VURE)(Level Five)
Assesses and documents the impacts and threats to the organisation. Creates reports and shares knowledge and insights with others.
Networking and communities (VURE)(Level Five)
Maintains a strong external network within own area of specialism.
Body of knowledge (VURE)(Level Five)
Gathers information on new and emerging threats and vulnerabilities. Contributes research findings on security vulnerabilities, countermeasures, and mitigations to national and international vulnerability databases.
Tools and techniques (VURE) (Level 4)
Specifies requirements for environment, data, resources, techniques and tools to perform vulnerability assessments.
Research activities (VURE) (Level 4)
Designs and executes complex vulnerability research activities into new threats, attack vectors, risks and potential solutions.
Reporting (VURE) (Level 4)
Reviews test results and modifies tests if necessary. Creates reports to communicate methodology, findings and conclusions.
Networking and communities (VURE) (Level 4)
Makes an active contribution to research communities.
Tools and techniques (VURE) (Level 3)
Applies tools, such as disassemblers, debuggers and fuzzers, to the analysis of embedded devices and/or the reverse engineering of hardware or software.
Research activities (VURE) (Level 3)
Applies standard techniques and tools for vulnerability research into new threats, attack vectors, risks and potential solutions.
Reporting (VURE) (Level 3)
Analyses and reports on research activities and results.
Networking and communities (VURE) (Level 3)
Participates in research communities and uses available resources to maintain current knowledge of malware attacks and other cyber security threats.