وظيفة مهندس Penetration Testing & Red Team Engineer شاغرة لدى VaporVM بالرياض
تفاصيل الوظيفة
تسعى شركة VaporVM إلى توظيف مهندس اختبار اختراق وفريق أحمر (Penetration Testing & Red Team Engineer) في الرياض، السعودية، للعمل على اختبارات أمنية متقدمة في بيئات الويب والتطبيقات والبنية التحتية.
المهام والمسؤوليات
- إجراء تقييم الثغرات واختبار الاختراق (VAPT) لبيئات الويب والتطبيقات وواجهات API والشبكات والسحابة والبنية التحتية.
- تنفيذ اختبارات أمنية بنماذج الصندوق الأسود والرمادي والأبيض.
- إجراء أنشطة الفريق الأحمر (Red Team) مثل تعداد النطاق، رفع الصلاحيات، سرقة بيانات الاعتماد، الحركة الجانبية، Reverse Shells، واختبار تجاوز الضوابط الأمنية.
- اختبار أمن تطبيقات الويب والجوال لنظامي Android وiOS.
- اختبار أمن واجهات API لخدمات REST وSOAP.
- إجراء اختبار اختراق للخدمات الدليلية النشطة (Active Directory) والبنية التحتية.
- إجراء تحليل ثابت وديناميكي (SAST/DAST) ومراجعة كود المصدر باستخدام أدوات مثل Fortify وSonarQube والتقنيات ذات الصلة.
- مراجعة التكوين الأمني والامتثال وفقًا لمعايير CIS Benchmarks.
- تحديد الثغرات والتحقق منها وترتيب أولوياتها مع استبعاد النتائج الإيجابية الكاذبة.
- إعداد تقارير تقييم أمنية مفصلة تتضمن توصيات المعالجة وتسليمها للعملاء.
- التعاون مع فرق التطوير والبنية التحتية والأمن لدعم معالجة الثغرات وتبني الممارسات الآمنة.
المهارات المطلوبة
- معرفة قوية بقوائم OWASP Top 10 وSANS Top 25 ومبادئ VAPT ومنهجيات اختبار الاختراق.
- خبرة عملية مع Burp Suite، ZAP، Nessus، Nmap، Metasploit، Acunetix، OpenVAS، SQLMap، Wireshark والأدوات ذات الصلة.
- خبرة في Frida، Objection، MobSF، Drozer، Jadx لاختبار أمن الأجهزة المحمولة.
- معرفة بأمن الخدمات السحابية AWS وAzure.
- مهارات قوية في إعداد التقارير والتوثيق والتواصل والتعامل مع العملاء.
الشروط والمتطلبات
- خبرة عملية قوية في VAPT وأمن التطبيقات والبنية التحتية والفريق الأحمر.
- الشهادات ذات الصلة مثل OSCP، CRTP، eWPT، eJPT، CAP، أو CEH (مفضلة). شهادة OSCP قيد الإنجاز حاليًا.
عرض النص الأصلي للإعلان
We are looking for a Penetration Testing & Red Team Engineer with strong hands-on experience in VAPT, web and mobile application security, infrastructure penetration testing, API security, Active Directory, and red teaming.
Key Responsibilities
- Conduct Vulnerability Assessment and Penetration Testing (VAPT) for web, mobile, API, network, cloud, and infrastructure environments.
- Perform Black Box, Grey Box, and White Box security assessments.
- Conduct Red Team activities, including domain enumeration, privilege escalation, credential dumping, lateral movement, reverse shells, and security-control bypass testing.
- Perform Web and Mobile Application Security Testing for Android and iOS applications.
- Conduct API security testing for REST and SOAP services.
- Perform Active Directory and Infrastructure Penetration Testing.
- Conduct SAST/DAST and Source Code Reviews using tools such as Fortify, SonarQube, and related technologies.
- Perform security configuration and compliance reviews against CIS Benchmarks.
- Identify, validate, and prioritize vulnerabilities while eliminating false positives.
- Prepare detailed security assessment reports, remediation recommendations, and client deliverables.
- Work with development, infrastructure, and security teams to support vulnerability remediation and secure practices.
Required Skills
- Strong knowledge of OWASP Top 10, SANS Top 25, VAPT, and penetration testing methodologies.
- Hands-on experience with Burp Suite, ZAP, Nessus, Nmap, Metasploit, Acunetix, OpenVAS, SQLMap, Wireshark, and related tools.
- Experience with Frida, Objection, MobSF, Drozer, Jadx for mobile security testing.
- Knowledge of AWS and Azure security.
- Strong reporting, documentation, communication, and client-facing skills.
Certifications
Relevant certifications such as OSCP, CRTP, eWPT, eJPT, CAP, or CEH are preferred. OSCP is currently in progress.
رقم الإعلان لدى المصدر: 4472523568