Application Security Engineer Penetration Testing
Navigos Search's Client
Mô tả công việc
About the Role: We are looking for an experienced Application Security Engineer with strong penetration testing skills to strengthen application and cloud security across our technology environment. The role will focus on identifying and validating security vulnerabilities across web applications, APIs, mobile applications, and cloud services, while working closely with development and infrastructure teams to improve the overall security posture. You will combine hands-on security testing with vulnerability research, security automation, and secure development guidance. Key Responsibilities: - Conduct manual and automated security assessments of web applications and APIs, following OWASP methodologies and industry standards. - Perform penetration testing on enterprise web-based systems and identify vulnerabilities through both automated tools and manual techniques. - Review findings generated by SAST, DAST, and SCA solutions, validate their accuracy, and distinguish genuine vulnerabilities from false positives. - Develop Proof-of-Concept exploits to demonstrate the impact and exploitability of identified vulnerabilities, including CVE-related issues. - Conduct security testing of Android and iOS applications, including vulnerability identification and validation. - Investigate emerging security vulnerabilities and conduct vulnerability research, including potential previously unknown issues. - Support vulnerability disclosure processes and CVE registration where applicable. - Work with software engineers and development teams to provide recommendations on secure coding and vulnerability remediation. - Collaborate with Backend, DevOps, Cloud, and QA teams to address security issues and improve secure system design. - Participate in security architecture reviews, threat/risk assessments, and security discussions throughout the development lifecycle. - Conduct security assessments of cloud-based environments, particularly AWS and GCP. - Develop scripts and security automation using Python, Go, Bash, or similar languages to improve testing efficiency and security workflows. - Prepare clear and detailed technical reports covering vulnerabilities, risk levels, evidence, impact, and remediation recommendations.
Yêu cầu công việc
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, Software Engineering, or a related discipline. - Hands-on experience in Application Security, Vulnerability Assessment, or Penetration Testing. - Strong knowledge of the OWASP Top 10 and secure software development principles. - Practical experience using and reviewing results from SAST, DAST, and SCA tools. - Ability to reproduce vulnerabilities and create PoCs/exploits, with experience handling CVE-level vulnerabilities. - Understanding of common security technologies such as Firewalls, VPN, IDS/IPS, and EDR. - Good understanding of core IT infrastructure, including networking, web/application servers, databases, and operating systems. - Proficiency in at least one scripting/programming language such as Python, Go, or Bash. - Hands-on experience with mobile application security testing on Android and/or iOS. - Strong analytical, problem-solving, technical documentation, and communication skills. - Sufficient English proficiency to communicate and collaborate effectively with international technical teams. - Security certifications such as OSCP or CEH are highly valued. Preferred Qualifications: - Track record of achievement in CTF competitions or other recognized security challenges. - Experience discovering previously unknown vulnerabilities and supporting CVE disclosure/assignment processes. - Practical experience assessing security in AWS, GCP, or other cloud environments. - Familiarity with DevSecOps, CI/CD security controls, and security automation. - Experience with threat modeling, security architecture, or secure design reviews. - Strong interest in vulnerability research and keeping up to date with emerging security threats and attack techniques.
Quyền lợi
13th monthly salary, Performance Bonus , Healthcare Plan and Insurance package , Professional FDI working environment