← к выдаче
безопасность

Application Security Engineer (Remote: US based - Senior and above)

вчера

Описание от работодателя

At Doyensec ( https://doyensec.com/ ), we believe that quality is the natural product of passion and care. We love what we do and we routinely take on difficult engineering challenges to help our customers build with security. Our clients are some of the leading global brands in the tech and startup communities. We help them secure their software and systems by providing information security consulting services (pentesting, reverse engineering, product security design and auditing). We keep a small dedicated client base and expect to develop long-term working relationships with the projects and people with whom we work. We are looking for a highly experienced security engineer to join our consulting team. We perform gray-box security testing on complex web and mobile applications. We need someone who has proven testing skills across multiple languages and environments and can hit the ground running. If you are good at crawling around in the ventilation ducts of the world’s most popular and important applications, you probably have the right skill set for the job. Experience developing code and tools is highly desirable, along with the ability to support the growth of fellow engineers. We offer a competitive salary in a supportive and dynamic environment that rewards hard work and talent. We are dedicated to providing research-driven application security and therefore invest 25% of your time exclusively to research, where we build security testing tools, discover new attack techniques, and develop countermeasures. Responsibilities: Security testing of web, mobile (iOS, Android) applications Vulnerability research activities, coordinated and executed with Doyensec's founders Partnering with customers to ensure the projects objectives are achieved Leading projects and supporting engineer growth Conducting cloud based audits on popular cloud platforms Providing support and guidance for clients concerning app and cloud security configuration, hardening and industry best practices Required Skills, Experience and Knowledge : At least 2 years of substantial professional experience focused specifically on application security testing or development, including performing security audits, or equivalent demonstrated experience through substantial and documented participation in bug bounty programs, CTFs, or similar security research activities. Proven ability to discover, document and fix security bugs in real-world applications (e.g., CVEs, publicly documented research, open source application security contributions or significant quality bug bounty work) Passion about understanding complex systems and the ability to have fun while doing it Ability to read and quickly comprehend modern coding languages (e.g., JavaScript, Python, TypeScript, Go) Familiarity with modern coding frameworks and their security measures Expert-level skills testing web and mobile applications Expert-level skills with Burp Suite Eager to learn, adapt, and perfect your work Additional Qualifications Experience performing cloud security assessments Experience with low-level/compiled language testing Experience with hardware testing Practical cryptography experience as used in real-world applications Substantial participation in CTFs (individually or making significant contributions to a team) Formal education or training in application security (related college degree, high-level training), or relevant certifications (e.g., OSCP, BSCP, OSWE, OSWA, GXPN, GPEN, OSED, OSEP, OSCE) We offer: Remote work (from anywhere in the USA), with flexible hours Competitive salary, including performance-based bonuses Startup atmosphere 25% research time (really!) Access to high-visibility security testing efforts for leading tech companies Possibility to attend and present at various security conferences around the globe Paid time off Company retreats and get together budget