Application Security Engineer (Remote: US based - Senior and above)
Описание от работодателя
At Doyensec ( https://doyensec.com/ ), we believe that quality is the natural product of passion and care. We love what we do and we routinely take on difficult engineering challenges to help our customers build with security.
Our clients are some of the leading global brands in the tech and startup communities. We help them secure their software and systems by providing information security consulting services (pentesting, reverse engineering, product security design and auditing). We keep a small dedicated client base and expect to develop long-term working relationships with the projects and people with whom we work.
We are looking for a highly experienced security engineer to join our consulting team. We perform gray-box security testing on complex web and mobile applications. We need someone who has proven testing skills across multiple languages and environments and can hit the ground running. If you are good at crawling around in the ventilation ducts of the world’s most popular and important applications, you probably have the right skill set for the job. Experience developing code and tools is highly desirable, along with the ability to support the growth of fellow engineers.
We offer a competitive salary in a supportive and dynamic environment that rewards hard work and talent. We are dedicated to providing research-driven application security and therefore invest 25% of your time exclusively to research, where we build security testing tools, discover new attack techniques, and develop countermeasures.
Responsibilities:
Security testing of web, mobile (iOS, Android) applications
Vulnerability research activities, coordinated and executed with Doyensec's founders
Partnering with customers to ensure the projects objectives are achieved
Leading projects and supporting engineer growth
Conducting cloud based audits on popular cloud platforms
Providing support and guidance for clients concerning app and cloud security configuration, hardening and industry best practices
Required Skills, Experience and Knowledge :
At least 2 years of substantial professional experience focused specifically on application security testing or development, including performing security audits, or equivalent demonstrated experience through substantial and documented participation in bug bounty programs, CTFs, or similar security research activities.
Proven ability to discover, document and fix security bugs in real-world applications (e.g., CVEs, publicly documented research, open source application security contributions or significant quality bug bounty work)
Passion about understanding complex systems and the ability to have fun while doing it
Ability to read and quickly comprehend modern coding languages (e.g., JavaScript, Python, TypeScript, Go)
Familiarity with modern coding frameworks and their security measures
Expert-level skills testing web and mobile applications
Expert-level skills with Burp Suite
Eager to learn, adapt, and perfect your work
Additional Qualifications
Experience performing cloud security assessments
Experience with low-level/compiled language testing
Experience with hardware testing
Practical cryptography experience as used in real-world applications
Substantial participation in CTFs (individually or making significant contributions to a team)
Formal education or training in application security (related college degree, high-level training), or relevant certifications (e.g., OSCP, BSCP, OSWE, OSWA, GXPN, GPEN, OSED, OSEP, OSCE)
We offer:
Remote work (from anywhere in the USA), with flexible hours
Competitive salary, including performance-based bonuses
Startup atmosphere
25% research time (really!)
Access to high-visibility security testing efforts for leading tech companies
Possibility to attend and present at various security conferences around the globe
Paid time off
Company retreats and get together budget