استخدام Senior Web Application Penetration Tester
شرح موقعیت شغلی
We are looking for a Senior Web Application Penetration Tester with strong hands-on experience finding and exploiting complex vulnerabilities in modern web applications and APIs.
Key Responsibilities:
- Perform advanced web application and API penetration tests
- Identify and exploit authentication and authorization flaws, privilege escalation, and broken function-level access control.
- Find business-logic vulnerabilities, race conditions and workflow bypasses.
- Exploit SSRF, SQL injection, XSS, insecure file upload, command injection.
- Test OAuth2/OIDC, SSO, JWT and session-management implementations.
- Perform advanced reconnaissance: subdomain and asset discovery, content discovery, parameter mining, JS analysis and endpoint extraction.
- Maintain and improve internal recon automation and tooling.
- Continuously monitor the external attack surface for new and forgotten assets.
Requirements:
- Expert-level Burp Suite usage, including extensions and custom tooling.
- Deep understanding of JWT, caching, proxies and modern web architectures.
- Advanced authentication and authorization testing skills.
- Strong business-logic and race-condition testing capability.
- Strong API security knowledge.
- Practical experience with Nuclei, ffuf, sqlmap.
مهارتهای مورد نیاز
- Security
- Web Applications
- API
حداقل سابقه کار
- سه تا شش سال
جنسیت
- مهم نیست
وضعیت نظام وظیفه
- مهم نیست