Security Engineer – Penetration Testing Expert
What you’ll do
Tribe IT DevOps Platform is looking for a qualified security test analyst with recent and relevant working experience as a software security tester. Security testing experience in a Financial environment could be advantageous but not determinant. You’ll be responsible for the execution of security tests on a wide variety of internal and external facing applications.
You also will assist with the continuous improvement of the processes critical to the success of the team. In this role, you will be helping DevOps teams thought-out SDLC.
How to succeed
Primary responsibility to provide internal and external network penetration testing, create actionable reporting based on findings, application testing, including black-, grey-, white box, code reviews and reverse engineering, software development advisory, network and software architecture reviews and guidance, social engineering, physical and red team engagements.
Additionally, you will support with pre intakes/technical intakes, development of security solutions and services, leveraging a robust technology portfolio, to address complex industry recognized information security trends and challenges faced by our respective clients. Assist with the delivery of pre-sales and post-sales support of the technical security solutions and services.
What do we expect?
- B.S. in Computer Science or related technical major (M.S./PhD preferred), or significant job experience.
- You have a valid (Current) ECPPT, OSCP, ECSA, GIAC Pentest Certification.
- Minimum 5 years penetration testing experience, with experience on mobile testing and APIs
- Experience with OWASP testing Guide / Open Source Security Testing Methodology Manual
- Fluent in at least 1 programming language.
- Expert with common web application penetration testing tools including, but not limited to Burp, Fiddler, OWASP Zap, BeEF, and at least one commercial solution (WebInspect, AppScan, or similar).
- Experience deploying enterprise security testing solutions.
- Familiarity with common network vulnerability and penetration testing tools including, but not limited to, Metasploit, vulnerability scanners, Kali Linux, and Nmap.
- Experience with debuggers, disassemblers, binary patch diffing (e.g. BinDiff).
- Experience with testing automation suites such as Cucumber, Jasmine, Selenium.
- Experience with cryptography, X509 certificates, signatures, securing TLS/SSL parameters, and certificate pinning.
- Technical depth in many, if not most of the following areas: Java EE, Node.js, Scala, iOS, Android OS, Windows Mobile, web services.
- Familiarity with Secure Development Lifecycle practices and Agile development with Continuous Delivery / Integration.
- Thought leadership in the security field, with demonstrable contributions to industry groups strongly desired.
- Artful communication skills and organizational savvy, to steer peers and leadership toward solutions that carefully balance business, risk, compliance, and engineering concerns.
- Eagerness to challenge the status quo, balanced with a reasonable and methodical approach to effecting change.
- A fun and positive attitude!
What we offer
- A salary tailored to your qualities and experience
- Reimbursement for travel expenses
- 24 vacation days with a 36-hour working week. If you work 40 hours a week, you will receive 27 vacation days
- Pension scheme
- 13th-month salary
- Individual Savings Contribution (BIS), 3.5% of your gross annual salary
- 8% Holiday payment
- Personal growth and challenging work with endless possibilities to realize your ambitions
- An informal working environment with innovative colleagues who strive for the very best
- Progressive way of working according to the Agile method, so that new ideas come to life
With around 52,000 employees and operations in approximately 40 countries, there is no shortage of opportunities for people with initiative who want to make a diﬀerence.
We hire smart people like you for your potential, not your past. Our biggest expectation is that you’ll stay curious. Keep learning. Take on more responsibility. In return, we’ll back you to develop into an even more awesome version of yourself.
If you want to work at the cutting edge of what’s possible, surrounded by progressive, inspiring and supportive colleagues, there is no better place to invest your talents than at ING.
Join us. Apply today.