דלג לתוכן הראשי

Application Security Researcher

Aliceרמת גן, ישראלהיברידיFull-timeדרגה: בכיר/ה

פורסם 18 ביוני · 0 מועמדים

שכר לא צוין במשרה זו

שמירה, הגשה או בדיקת התאמה — כמה שניות להקמת חשבון חינם.

תובנת Willbi

התפקיד במילים פשוטות

תפקיד זה כולל ביצוע מבדקי חדירות מתקדמים עבור אפליקציות ואינטרגרציות API של חברות גלובליות גדולות. העבודה כוללת השתתפות בפרויקטי Red Team, זיהוי נקודות תורפה ופיתוח כלי אבטחה ואוטומציה פנימיים.

חובה
  • 3+ years of proven, hands-on experience in application security analysis and complex API penetration testing
  • Mastery of the OWASP Top 10 landscape
  • Proficiency in scripting/automation with Python, JavaScript, or GoLang
  • Experience with static and dynamic analysis of Android and iOS applications (detours, hooking, runtime code manipulation)
  • Deep knowledge of latest offensive TTPs, advanced penetration testing, and network analysis
יתרון
  • Offensive security certifications (OSCP, OSWE, eWPTXv2, CRTP, etc.)
  • Demonstrated achievements/research on platforms like HackTheBox, Pwn2Own, TryHackMe, or Bug Bounty programs

חולץ מתיאור המשרה · מתעדכן אוטומטית

למי זה מתאים

התפקיד מתאים לאנשי אבטחת מידע עם לפחות 3 שנות ניסיון מעשי במבדקי חדירות לאפליקציות ו-API, לצד ידע בפיתוח בשפות כמו Python, JavaScript או Go. התפקיד פחות מתאים למי שחסר ניסיון ניכר בניתוח אפליקציות מובייל ובשימוש בכלי הנדסה לאחור.

תיאור המשרה המלא

המשרה המקורית · נשמר לעיון

We are seeking a highly motivated and technically proficient Senior Penetration Tester to join our security research division. This role is dedicated to performing advanced offensive security assessments against the biggest companies in the world You need to be independent, attentive to details, organized, eager to learn new things, and like to research and solve problems What you’ll do: • Lead and execute comprehensive, technically rigorous penetration tests targeting complex web applications, modern API architectures, and enterprise systems for organizations with significant global presence. • Engage in sophisticated Red Team projects, including the identification of undisclosed API endpoints, development of novel bypass techniques for established security controls, and lateral movement within target environments. • Contribute substantively to the design, development, and maintenance of proprietary internal security tools and automation frameworks to enhance the efficacy and efficiency of offensive operations.

Requirements: Requirements: • Minimum of 3 years of proven, hands-on experience in application security analysis, with a heavy emphasis on complex API penetration testing and a mastery of the OWASP Top 10 landscape. • Proficiency in developing and automating tasks using at least one language like Python, JavaScript, or GoLang. • Strong experience with static and dynamic analysis of Android and iOS applications, including hands-on experience with techniques like detours, hooking, and runtime code manipulation • Deep, hands-on knowledge of the latest tactics, techniques, and procedures (TTPs) used in advanced penetration testing and network analysis. • Ability to author comprehensive and technically rigorous reports detailing identified vulnerabilities and research outcomes. • Hands-on experience with industry-standard reversing tools like JADX, Ghidra, or IDA Pro. Nice to have: • OSCP, OSWE, eWPTXv2, CRTP, or other high-level offensive certifications. • Demonstrated online achievements, write-ups, or contributions on platforms such as HackTheBox, Pwn2Own, TryHackMe, Bug Bounty programs, or published security research.

אודות Alice
פרופיל החברה · בקרוב

ביקורות עובדים · בקרובעוד משרות ב-Alice

שאלות על המשרה

  • המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
Alice
פורסם 18 ביוני · 0 מועמדים
בדקו את ההתאמה