1 ساعت پیش | کد آگهی: 11859718
دستهبندی شغلی
موقعیت مکانی
تحصیلات
-
محل فعالیت
-
مزایا
-
مهارت ها و زبان ها
برنامه نویسی Java - برنامه نویسی PHP - کار با Linux - نرم افزار Microsoft Access - لاراول
نوع همکاری
سایر اطلاعات
We are looking for Senior Security Engineers to join Azki s Security team across three specialized areas
Cyber Defense Penetration Testing Application Security
You don t need to be experienced in all three areas We are looking for strong hands on expertise in at least one of these domains with the ability to collaborate across the broader security landscape
What You ll Do
Depending on your area of expertise you will contribute to one or more of the following security tracks
1 Cyber Defense Blue Team
Manage maintain and optimize the Splunk SIEM environment
Onboard and integrate security logs from servers endpoints network devices private cloud platforms and security tools
Create and maintain Splunk dashboards reports alerts searches and detection use cases
Develop and continuously improve security detection rules based on raw telemetry
Analyze security events and identify suspicious or malicious activity
Review and tune WAF rules to improve detection coverage and reduce false positives
Support automation and integration between Splunk and other security tools
Monitor data ingestion indexing performance and overall SIEM health
Work with Windows Linux network endpoint and Kubernetes telemetry
Apply MITRE ATT CK concepts to detection engineering and threat analysis
2 Penetration Testing Offensive Security
Perform advanced penetration tests against web applications and APIs
Identify and exploit authentication and authorization flaws privilege escalation and broken access control
Discover business logic vulnerabilities race conditions and workflow bypasses
Test for vulnerabilities including SSRF SQL Injection XSS insecure file upload command injection and related attack vectors
Assess OAuth2 OIDC SSO JWT and session management implementations
Perform advanced reconnaissance including subdomain and asset discovery content discovery parameter mining JavaScript analysis and endpoint extraction
Monitor and assess the external attack surface for new and forgotten assets
Maintain and improve internal reconnaissance automation and security tooling
Produce clear technical findings and proof of concept demonstrations of identified vulnerabilities
3 Application Security
Design implement and operate security controls across GitLab CI CD pipelines
Integrate and tune SAST SCA DAST secret detection IaC scanning and container image scanning
Generate and manage SBOMs and operate OWASP Dependency Track as a central component inventory
Operate and maintain security tooling such as Semgrep and SonarQube
Perform manual source code security reviews on Java and Laravel PHP applications
Identify injection access control deserialization SSRF file upload cryptographic and business logic weaknesses
Validate scanner findings eliminate false positives and translate security findings into actionable guidance for developers
Correlate source code review findings with penetration testing results to identify root causes and validate exploitability
Apply OWASP Top 10 OWASP API Security Top 10 and OWASP WSTG as part of application security assessments
Assess authentication and authorization mechanisms including OAuth 2 0 OIDC SAML JWT and SSO
Chain vulnerabilities into realistic attack paths and demonstrate their potential business impact
Depending on Your Area of Expertise
Cyber Defense
Hands on experience with Splunk Enterprise and or Splunk Enterprise Security
Strong knowledge of Splunk SPL
Hands on experience with WAF technologies including log analysis custom rule writing and tuning
Knowledge of MITRE ATT CK
Understanding of Windows Linux network endpoint and Kubernetes logs
Penetration Testing
Expert level experience with Burp Suite including extensions and custom tooling
Strong knowledge of modern web and API security
Advanced authentication and authorization testing skills
Strong understanding of JWT caching proxies and modern web architectures
Practical experience with Nuclei ffuf and sqlmap
Strong business logic and race condition testing capabilities
Application Security
Hands on experience with GitLab CI CD security tooling
Experience with SAST SCA DAST secret detection IaC and container security scanning
Experience with tools such as Semgrep SonarQube and OWASP Dependency Track
Practical experience with source code security review particularly Java and Laravel PHP applications
Strong understanding of OWASP Top 10 OWASP API Security Top 10 and secure software development practices
شرکت ازکی Azki
دسته بندی IT DevOps Server
نحوه همکاری تمام وقت
نوع همکاری حضوری
مدرک تحصیلی مهم نیست
سابقه کار سه تا شش سال
حقوق توافقی
جنسیت مهم نیست
مهارت ها تست نفوذ OWASP امنیت
شهر تهران تهران
جویا کار این آگهی را از سایت
جابینجا
استخراج نموده است و هیچ مسئولیتی در قبال این آگهی ندارد.
دقت نمایید که کارفرما حق دریافت هیچ گونه وجهی از کارجو را نداشته و این امر خلاف قانون است. در صورت مشاهده این موارد یا سایر تخلفات با کلیک روی (گزارش آگهی) ما را در ارائه خدمات بهتر یاری نمایید.
در غیر این صورت میتوانید با کلیک بر روی دکمه "درج نظر" نظر خود را در مورد این آگهی ثبت کنید.
جهت اشتراک در شبکه های اجتماعی روی کلیدهای زیر کلیک کنید
همچنین میتوانید لینک کوتاه زیر را جهت دسترسی به صفحه فوق برای اشتراک گذاری کپی کنید
کپی کردن لینک
نظرات در مورد این آگهی: درج نظر