Description


Job description-
Develop/modify custom tooling to solve new needs
- Build relationships with engineering teams to drive Client to a mature security state
- Conduct full exploitation operations in Windows and *nix environments
- Develop comprehensive and accurate reports and presentations for both technical and executive audiences
- Communicate findings and strategy to client stakeholders, including technical staff, executive leadership, and legal counsel
- Perform innovative research and promote an environment of innovation and knowledge sharing
- Perform web application testing, mobile application testing, network penetration testing, and source code reviews
- Utilize attacker tools, tactics, and procedures to perform analysis and identify vulnerabilities
- Implement static and dynamic security testing as part of an automated application security testing process
- Other Cybersecurity operational and project initiatives responsibilities to be assigned

Qualifications
- Bachelors’ Degree or industry equivalent work experience in IT, Computer Engineering or a similar field
- 7+ years of experience performing application penetration tests
- Well-rounded background in cloud, network, and system security
- Experience with reading, writing, and editing code written in various programming languages, such as Perl, Python, Ruby, Bash, C/C++, C#, and Java
- Experience with Burp Suite Pro, including identification and usage of relevant plugins
- Experience with security assessment tools, including Nessus, Accunetix, Metasploit, or Cobalt Strike
- Experience with conducting reverse engineering on mobile applications, including applications with anti-emulator and obfuscation protections
-
Preferred Qualifications:
- Industry certifications such as OSCP, OSCE, OSWE, GPEN, GCIH, GWAPT, or GXPN
- Contributions to the security community such as research, public CVEs, bug-bounty recognitions, open-source projects, blogs, publications, etc
- Experience with server administration, TCP/IP networking, vulnerability identification and exploitation, vulnerability exploit code development, offensive security operation coordination and communication, vulnerability tracking and remediation, mobile testing
- Experience with methodologies on both static and dynamic analysis for different application types and platforms
- Experience working with Web Application Firewalls
- Securing, testing, having a good understanding of API vulnerabilities and how to address them

Education

Any Graduate