Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой — после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Life at Bir provides financial services and operates a Product Security team that supports security assessments, threat modeling, and security architecture reviews across products and services.
задачи
Lead application security assessments, threat modeling sessions, and architecture reviews for products and services;
Perform comprehensive penetration testing across web, mobile, API, and infrastructure environments;
Conduct SAST, DAST, and SCA analysis; fine-tune scanning tools and integrate findings into development workflows;
Collaborate with development teams to embed security controls within CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins);
Work with DevOps teams to assess and improve cloud security posture across AWS, GCP, and Azure;
Investigate and respond to product security incidents and vulnerability reports;
Define and enforce secure coding practices, security guidelines, and standards across engineering teams;
Mentor mid and junior level security engineers and contribute to the growth of the Product Security team;
Produce detailed security assessment reports and executive-level summaries.
требования
4+ Years of experience in Application Security, Product Security, or Penetration Testing roles;
Hands-on experience with Active Directory attacks including Kerberoasting, Pass-the-Hash, DCSync, LDAP enumeration, and privilege escalation paths;
Proficiency with BloodHound, Impacket, Mimikatz, CrackMapExec, and Rubeus;
Deep familiarity with OWASP API Security Top 10 and OWASP Mobile Security Testing Guide (MSTG);
Strong hands-on experience with web application, mobile (iOS/Android), and API penetration testing, including complex attack vectors;
Hands-on experience with cloud security assessments across AWS, Azure, and/or GCP, including IAM policies, KMS, network controls, and misconfiguration detection;
Ability to review system and application architectures and provide actionable security recommendations;
Experience performing threat modeling using STRIDE, PASTA, or similar methodologies;
Understanding of AI/ML security risks and familiarity with the MITRE ATLAS framework and its application to AI system threat modeling;
Experience with Red Team and Purple Team campaigns and familiarity with the MITRE ATT&CK and the Cyber Kill Chain;
Proficiency with Burp Suite Pro, OWASP ZAP, Nmap, Metasploit, Frida, objection, and MobSF;
Scripting proficiency in Python, Bash, or PowerShell for security automation tasks;
Understanding of container and Kubernetes security concepts;
Nice to have: OSWE, OSEP, CAPE, OSCP, BSCP, CRTE, CRTO, AWS Security Specialty, or equivalent certifications.