You will join a growing team responsible for building a secure infrastructure that supports the technical & product teams. With your background in security, you will conduct formal both automated and manual penetration tests using approved standard methodologies to identify and exploit vulnerabilities in networks, systems, and applications, assess security controls for large enterprise systems and applications, and hosting infrastructure, and document technical and logical security findings identified during the security assessments, and report them in a timely manner.
Responsibilities and Duties
Performs threat modeling to identify all possible attack vectors
Select and conduct, and review vulnerability assessment and penetration testing against a wide array of technologies and platforms, and act as security advisor to business unit partners
Track public and privately released vulnerabilities and assist in the triage process
Perform black box and gray box testing, source code analysis, manual pen testing, and vulnerability assessments
Perform hands-on technical validation of vulnerability to determine the risk to different configurations and priorities for remediation
Communicate current cybersecurity threats and educate stakeholders on risks and recommendations
Conduct relevant research, data analysis, and create reports
Qualifications
University Degree in Computer Science, Computer Engineering, or other relevant fields.
3+ years of operational experience in Information Technology & Information Security.
Understanding of commonly used Internet protocols such as SMTP, HTTP, and DNS.
Familiar with Security Regulations and Standards.
Experience with API testing, Mobile Application Testing, and penetration testing frameworks
Familiarity with penetration testing tools and tool suites such as Burp Suite, OWASP ZAP, Kali Linux, etc.
An aptitude for technical writing, including assessment reports and presentations
Understanding of offensive security, including offensive evasion techniques
Strong knowledge of Open Web Application Security Project (WEB and Mobile)
Hands-on experience with two or more scripting languages such as Python, Powershell, Bash, or Ruby
معرفی شرکت
اسنپفود بزرگترین سرویس آنلاین سفارش غذا در ایرانه که در کنار غذا، سرویسهایی از جمله سفارش نان، پروتئین، شیرینی و میوه رو هم در خودش داره.
همراهی صمیمانه و اعتماد بیش از ۵ میلیون کاربر ما رو بر این داشته که همواره به دنبال خلق پدیدههای تازه و راهی برای خدمترسانی بهتر و باکیفیتتر باشیم.
ما در این مسیر علاقهمند به همکاری با افرادی هستیم که با هوشمندی و سرعت عملشون در عبور از چالشها و مسائل کسبوکار یاریگرمون باشن.