استخدام Penetration Testing Engineer
شرح موقعیت شغلی
You will join a growing team responsible for building a secure infrastructure that supports the technical & product teams. With your background in security, you will conduct formal both automated and manual penetration tests using approved standard methodologies to identify and exploit vulnerabilities in networks, systems, and applications, assess security controls for large enterprise systems and applications, and hosting infrastructure, and document technical and logical security findings identified during the security assessments, and report them in a timely manner.
Responsibilities and Duties
- Performs threat modeling to identify all possible attack vectors
- Select and conduct, and review vulnerability assessment and penetration testing against a wide array of technologies and platforms, and act as security advisor to business unit partners
- Track public and privately released vulnerabilities and assist in the triage process
- Perform black box and gray box testing, source code analysis, manual pen testing, and vulnerability assessments
- Perform hands-on technical validation of vulnerability to determine the risk to different configurations and priorities for remediation
- Communicate current cybersecurity threats and educate stakeholders on risks and recommendations
- Simulate cyberattacks to identify vulnerabilities
- Performs static source code vulnerability analysis
- Conduct relevant research, data analysis, and create reports
Qualifications
- University Degree in Computer Science, Computer Engineering, or other relevant fields.
- 3+ years of operational experience in Information Technology & Information Security.
- Understanding of commonly used Internet protocols such as SMTP, HTTP, and DNS.
- Familiar with Security Regulations and Standards.
- Experience with API testing, Mobile Application Testing, and penetration testing frameworks
- Familiarity with penetration testing tools and tool suites such as Burp Suite, OWASP ZAP, Kali Linux, etc.
- An aptitude for technical writing, including assessment reports and presentations
- Understanding of offensive security, including offensive evasion techniques
- Strong knowledge of Open Web Application Security Project (WEB and Mobile)
- Hands-on experience with two or more scripting languages such as Python, Powershell, Bash, or Ruby
مهارتهای مورد نیاز
- HTTP
- Python
- PowerShell
- Bash
- HTML
جنسیت
- مهم نیست
وضعیت نظام وظیفه
- مهم نیست