jobs in PCSS

全职 VAPT Engineer 工作, 薪水, PCSS 公司招聘中 - Ricebowl

VAPT Engineer

PCSS

Undisclosed

Singapore

分享
保存

工作地点

  • Singapore

职位描述

岗位职责

Pre-Requisti

  • Degree in Computer Engineering, Computer Science, Information Systems, Digital Forensics or equivalent qualifications
  • Minimum 2 years’ of relevant work experience in IT security implementation and operations
  • Good interpersonal skills and a team player


Job Description:

  • Perform application and infrastructure penetration tests for customers
  • Conducting application security assessments and penetration tests (web, mobile, web service, etc.). Assessments involve manual testing and analysis as well as the use of automated application vulnerability scanning/testing and/or code review tools i.e. Burp Suite Professional, HP Fortify or Checkmarx
  • Writing a formal security assessment report for each application, using our company’s standard reporting format
  • Participating in conference calls or on client’s site with potential client to scope out newly requested security projects and estimate the amount of time required to complete the project and current clients to review assessment results and consult with the clients on remediation options
  • Retesting security vulnerabilities and republishing reports to indicate the retesting results
  • Perform security reviews of application designs, source code and deployments as required, covering all types of applications (web application, web services, mobile applications, thick client applications, SaaS)
  • Work on improvements for provided security services, including the continuous enhancement of existing methodology material and supporting assets
  • Report and present on findings


Technical Skills:-

  • Experience with various security tools and products (Fortify, AppScan, Nessus etc)
  • Familiar with developing web and/or mobile applications, preferably involving complex financial, e-commerce, or enterprise business solutions
  • Knowledge of the HTTP protocol and understand how it works
  • Experience performing application security testing using manual techniques plus runtime vulnerability testing tools and/or code review tools
  • Experience with network/infrastructure-level penetration testing (preferred)
  • Understanding of cryptography principles
  • Possessed OSCP or attained CREST


重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多