Senior Application and Cloud Penetration Tester
Seeking an experienced offensive cybersecurity specialist to lead end-to-end penetration testing across applications, source code, APIs, and cloud infrastructure in collaboration with development and DevOps teams.
Responsabilidades
- Lead end-to-end application, code, and cloud penetration tests.
- Identify complex security vulnerabilities and provide code- and infrastructure-level remediation recommendations.
- Work closely with development and DevOps teams in Agile and CI/CD environments.
Requisitos
- At least 3 years of hands-on penetration testing experience.
- Proven experience testing Web applications, SaaS products, and complex backend systems, including isolated networks.
- Practical backend and frontend development experience.
- Experience conducting penetration tests in AWS, Azure, or GCP environments.
- Strong command of the OWASP Top 10.
- Hands-on manual code review using Python, Java, C#, and JavaScript/Node.js.
- Deep understanding of API security across REST, GraphQL, and gRPC.
- Knowledge of OAuth2, OIDC, and SAML authentication protocols.
- Ability to write automation scripts in Python, Bash, or PowerShell.
- Experience writing technical and management reports in Hebrew and English.
Se valora
- OSCP, OSWE, BSCP, AWS Certified Security, or Azure Security Engineer (AZ-500) certification.
- Familiarity with OWASP Top 10 for LLM, including prompt injection and insecure output handling.
- Experience assessing AI service APIs such as OpenAI API and Azure AI Services.
- Experience with Kubernetes, Docker, cloud IAM role exploitation, cloud lateral movement, Active Directory, Azure AD, and common network attacks.