3.2 KiB
3.2 KiB
Tasks & work activities — ethical hacker
Source: O*NET 30.3, occupation 15-1299.04 (Penetration Testers).
Task statements
- [nan] Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters.
- [nan] Collect stakeholder data to evaluate risk and to develop mitigation strategies.
- [nan] Conduct network and security system audits, using established criteria.
- [nan] Configure information systems to incorporate principles of least functionality and least access.
- [nan] Design security solutions to address known device vulnerabilities.
- [nan] Develop and execute tests that simulate the techniques of known cyber threat actors.
- [nan] Develop infiltration tests that exploit device vulnerabilities.
- [nan] Develop presentations on threat intelligence.
- [nan] Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests.
- [nan] Discuss security solutions with information technology teams or management.
- [nan] Document penetration test findings.
- [nan] Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries.
- [nan] Gather cyber intelligence to identify vulnerabilities.
- [nan] Identify new threat tactics, techniques, or procedures used by cyber threat actors.
- [nan] Identify security system weaknesses, using penetration tests.
- [nan] Investigate security incidents, using computer forensics, network forensics, root cause analysis, or malware analysis.
- [nan] Keep up with new penetration testing tools and methods.
- [nan] Maintain up-to-date knowledge of hacking trends.
- [nan] Prepare and submit reports describing the results of security fixes.
- [nan] Test the security of systems by attempting to gain access to networks, Web-based applications, or computers.
- [nan] Update corporate policies to improve cyber security.
- [nan] Write audit reports to communicate technical and procedural findings and recommend solutions.
Detailed work activities
- Analyze risks to minimize losses or damages.
- Analyze security of systems, network, or data.
- Develop computer or information security policies or procedures.
- Develop computer or information systems.
- Develop organizational policies or programs.
- Develop testing routines or procedures.
- Discuss design or technical features of products or services with technical personnel.
- Evaluate characteristics of equipment or systems.
- Examine records or other types of data to investigate criminal activities.
- Interpret design or operational test results.
- Investigate illegal or suspicious activities.
- Prepare analytical reports.
- Prepare scientific or technical reports or presentations.
- Prepare technical or operational reports.
- Search files, databases or reference materials to obtain needed information.
- Stay informed about current developments in field of specialization.
- Test computer system operations to ensure proper functioning.
- Test performance of electrical, electronic, mechanical, or integrated systems or equipment.