Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
О рекламодателе
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ" ИНН: 9704271170
описание
The team strengthens the security of high-load products by identifying vulnerabilities across applications, infrastructure, cloud environments, and payment flows. It improves security through offensive security assessments and practical remediation in collaboration with engineering, product, fraud, and compliance teams.
задачи
Plan and execute penetration tests across web applications, APIs, mobile applications, internal and external infrastructure, and AWS cloud environments
Perform red team and assumed-breach exercises covering privilege escalation, lateral movement, persistence, and data exfiltration
Assess the security of cloud-native services, Kubernetes environments, microservices, and CI/CD pipelines
Identify vulnerabilities affecting payment systems, wallets, KYC/AML processes, bonus mechanisms, affiliate tracking, and other business-critical workflows
Work with Product, Engineering, AppSec, Payments, and Fraud teams to prioritize findings and support remediation
Develop custom scripts and internal tools to improve testing capabilities where standard solutions are insufficient
Contribute to threat modeling and support secure-by-design initiatives
Review penetration testing plans and reports, and provide technical guidance to junior and middle security specialists
Research emerging vulnerabilities, MITRE ATT&CK techniques, and security advisories, and translate them into actionable improvements
Support security assessments for new products, releases, and market launches, including effort estimation and pre-certification activities
Advise technical and business stakeholders on offensive security matters
требования
4+ Years of hands-on experience in penetration testing or offensive security
Practical experience in at least three areas: web applications/APIs, internal networks, external infrastructure, cloud environments (AWS/GCP), or mobile applications (iOS/Android)
OSCP or an equivalent offensive security certification
Strong knowledge of SAST, SCA, DAST, AWS/GCP, MITRE ATT&CK, OWASP ASVS, OWASP WSTG, and PTES
Good understanding of application architecture, including MVC and data flow principles
Knowledge of supply chain attack techniques
Experience writing scripts in Python and Bash
Understanding of IAM models within at least one major cloud provider
Strong reporting, documentation, and communication skills
Ability to balance security priorities with business and release deadlines
Solid understanding of security frameworks and compliance standards, including PCI DSS, ISO 27001, NIST, and GDPR
Upper-Intermediate English
Будет плюсом: advanced offensive security certifications such as OSWE, OSEP, OSED, CRTO, BSCP, ARTE, or GRTE; experience designing secure architectures for Kubernetes and AWS environments; previous background in iGaming, fintech, or payment products; public security research, CVEs, advisories, technical publications, or conference presentations; completion of HTB Pro Labs or strong CTF achievements; contributions to open-source offensive or defensive security projects
условия
Competitive salary based on experience
Paid annual leave and sick leave
Opportunities for professional and career growth
Supportive environment focused on continuous development and long-term growth