The Senior Security Engineer is part of Digikala’s Offensive Security team and is responsible for identifying and reducing security risks across web applications, APIs, and supporting services. The role exists to detect vulnerabilities before they can be exploited, support secure product delivery, and help development teams remediate security issues effectively. This position works closely with Development, DevOps, Cloud, SOC, Infrastructure, and Product teams.
Responsibilities:
Perform comprehensive black-box, grey-box, and white-box penetration testing of web applications, APIs, microservices, and internal services. Identify high-impact vulnerabilities, including authentication bypass, authorization issues, IDOR, SSRF, injection flaws, business logic weaknesses, and sensitive data exposure.
Complete assigned security assessments within agreed timelines and provide clear, reproducible, and risk-based reports.
Validate remediation actions and ensure that critical and high-severity vulnerabilities are properly resolved before production deployment.
Support DevSecOps processes by reviewing findings from SAST, DAST, secret scanning, dependency scanning, and container security tools.
Conduct threat hunting activities for exposed assets, vulnerable services, leaked credentials, public repositories, and newly published CVEs.
Provide practical remediation guidance and work directly with engineering teams to reduce security risks.
ما در دیجیکالا به عنوان شرکتی که در حوزه تجارت الکترونیک فعالیت میکنه، به دنبال تحقق رویای «لبخندی برای همه ایران» هستیم. در همین راستا، با بهرهگیری از فناوریهای روز دنیا و توسعه مداوم سرویسهای مبتنی بر تکنولوژی، ارزشهای خودمون رو در مشتریمحوری، اشتیاق برای تعالی، کارگروهی و نتیجهگرایی دنبال میکنیم.
در گروه دیجیکالا امکانی فراهم شده تا ما با افراد با تخصصهای متنوع در یک مجموعه فعالیت کنیم. علاوه بر این، با توجه به سرعت رشد بالا در دیجیکالا، امکان رشد و توسعه رو در مواجهه با چالشها و استفاده از برنامههای توسعه و آموزش متنوع داریم.