Application Penetration Tester
פורסם לפני 10 ימים · 0 מועמדים
התפקיד במילים פשוטות
התפקיד כולל ביצוע מבדקי חדירה (Penetration Testing) עבור אפליקציות ווב, מובייל וממשקי API, לצד ביצוע סקירות אבטחה ברמת ה-Design. ביומיום נדרש לבצע בדיקות ידניות ושימוש בכלים ייעודיים לגילוי חולשות, להשתתף במידול איומים ולהפיק דוחות מפורטים עם הנחיות לתיקון הסיכונים.
- 3+ years of experience performing hands-on penetration testing
- Proven experience testing web applications and infrastructure
- Penetration Testing certification required (e.g. eWPT, OSWE, GWAPT)
- Web, API, and mobile (iOS and Android) penetration testing
- Strong knowledge of OWASP Top 10, modern application attack techniques, and vulnerability classes
- Experience performing tests in compliance-driven environments (finance, healthcare, defense)
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
מתאים לאנשי אבטחת מידע בעלי ניסיון מעשי של 3 שנים לפחות במבדקי חדירה לאפליקציות ובעלי הסמכה מקצועית בתחום. פחות מתאים למי שאינו מחזיק בהסמכה מתאימה או שמחפש תפקיד ללא דרישה לכתיבת דוחות מפורטים.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןPerform web, mobile and API penetration testing, conduct application security design reviews, and recommend practical remediation strategies for identified risks. Minimum 3 years of hands-on experience in application PT, with strong knowledge of OWASP Top 10 and modern application attack techniques, and at least one recognized certification such as eWPT, OSWE or GWAPT.
What You'll Do:
• Plan and execute penetration tests on web applications, APIs and mobile applications.
• Perform authenticated and unauthenticated web application assessments such as logic flaws, injection vulnerabilities, insecure authentication, and access control issues.
• Test iOS and Android applications for common mobile security weaknesses.
• Use manual testing techniques supported by industry tools to discover security weaknesses.
• Produce high quality, detailed, accurate test reports with reproduction steps and risk based remediation guidance.
• Collaborate with stakeholders to scope engagements and define testing requirements.
• Participate in threat modeling and security design reviews.
• Stay current with emerging vulnerabilities, exploits, tools, and techniques.
Requirements:
• 3+ years of experience performing hands-on penetration testing.
• Proven experience testing web applications and infrastructure.
• Penetration Testing certification required (application ones such as eWPT, OSWE or GWAPT are preferred).
• Solid understanding of web technologies (HTTP, JavaScript, REST APIs) and mobile platforms.
• Familiarity with secure coding practices and common frameworks.
• Experience with common security testing tools such as Burp Suite, metasploit, mobile testing tools, and vulnerability scanners.
• Strong knowledge of vulnerability classes and exploit techniques.
• Demonstrated ability to document findings clearly and communicate technical issues effectively.
• Experience performing tests in compliance driven environments such as finance, healthcare or defense is a strong advantage.
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- 3+ years of experience performing hands-on penetration testing, Proven experience testing web applications and infrastructure, Penetration Testing certification required (e.g. eWPT, OSWE, GWAPT), Web, API, and mobile (iOS and Android) penetration testing, Strong knowledge of OWASP Top 10, modern application attack techniques, and vulnerability classes