сегодня

security engineer product security

ориентир по рынку
вакансия зп не указана
в среднем 343 365 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Life at Bir provides financial services and operates a Product Security team that supports security assessments, threat modeling, and security architecture reviews across products and services.

задачи

  • Lead application security assessments, threat modeling sessions, and architecture reviews for products and services;
  • Perform comprehensive penetration testing across web, mobile, API, and infrastructure environments;
  • Conduct SAST, DAST, and SCA analysis; fine-tune scanning tools and integrate findings into development workflows;
  • Collaborate with development teams to embed security controls within CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins);
  • Work with DevOps teams to assess and improve cloud security posture across AWS, GCP, and Azure;
  • Investigate and respond to product security incidents and vulnerability reports;
  • Define and enforce secure coding practices, security guidelines, and standards across engineering teams;
  • Mentor mid and junior level security engineers and contribute to the growth of the Product Security team;
  • Produce detailed security assessment reports and executive-level summaries.

требования

  • 4+ Years of experience in Application Security, Product Security, or Penetration Testing roles;
  • Hands-on experience with Active Directory attacks including Kerberoasting, Pass-the-Hash, DCSync, LDAP enumeration, and privilege escalation paths;
  • Proficiency with BloodHound, Impacket, Mimikatz, CrackMapExec, and Rubeus;
  • Deep familiarity with OWASP API Security Top 10 and OWASP Mobile Security Testing Guide (MSTG);
  • Strong hands-on experience with web application, mobile (iOS/Android), and API penetration testing, including complex attack vectors;
  • Hands-on experience with cloud security assessments across AWS, Azure, and/or GCP, including IAM policies, KMS, network controls, and misconfiguration detection;
  • Ability to review system and application architectures and provide actionable security recommendations;
  • Experience performing threat modeling using STRIDE, PASTA, or similar methodologies;
  • Understanding of AI/ML security risks and familiarity with the MITRE ATLAS framework and its application to AI system threat modeling;
  • Experience with Red Team and Purple Team campaigns and familiarity with the MITRE ATT&CK and the Cyber Kill Chain;
  • Proficiency with Burp Suite Pro, OWASP ZAP, Nmap, Metasploit, Frida, objection, and MobSF;
  • Scripting proficiency in Python, Bash, or PowerShell for security automation tasks;
  • Understanding of container and Kubernetes security concepts;
  • Nice to have: OSWE, OSEP, CAPE, OSCP, BSCP, CRTE, CRTO, AWS Security Specialty, or equivalent certifications.

условия

  • No conditions specified

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.