Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
The company is a global leader in software supply chain management, providing solutions to manage, accelerate, and secure software delivery from code to production for thousands of customers, including a majority of Fortune 100 companies.
задачи
Reshape product security;
Plan and execute advanced penetration testing campaigns;
Develop tools and frameworks for scalable security testing and fuzzing;
Lead security innovation by building and managing penetration testing tools and AI agents;
Analyze vulnerabilities, perform root cause analysis, and develop proofs of concept;
Identify systemic product weaknesses and define long-term mitigations;
Collaborate with engineering teams to reproduce, triage, and fix vulnerabilities;
Contribute to security research publications, CVE submissions, and industry knowledge sharing;
Evolve internal testing capabilities using modern tooling and AI-assisted approaches.
требования
5+ Years of experience in research and penetration testing;
Strong coding skills and deep technical understanding of web, API, cloud-native, and backend technologies;
Knowledge and experience in AI and LLM penetration testing;
Experience with penetration testing tools (Burp Suite, Metasploit, etc.) and custom security tools development;
Familiarity with modern architectures (Cloud, microservices, containers, Kubernetes);
Familiarity with secure software architecture and typical attack vectors;
Demonstrated ability to lead security testing engagements and report technical findings effectively;
Knowledge and hands-on experience with SSDLC tools and CI/CD pipelines;
Nice to have: Experience building or integrating automated PT or fuzzing pipelines, publications or open-source contributions in the security domain.