1 день назад
Threat Researcher (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Threat Researcher (Cybersecurity): Conducting red teaming and penetration testing across enterprise, cloud, and web application environments with an accent on adversary simulation, vulnerability exploitation, and offensive security research. Focus on developing attack tooling and automation, evading security monitoring, chaining high-impact vulnerabilities, and communicating remediation risks to customer engineering and management teams.
Location: Taipei, Taiwan
Company
is a global cybersecurity software company developing technologies that protect connected systems and enterprise environments.
What you will do
- Perform red teaming and penetration testing against customer enterprise environments, including cloud applications and infrastructure.
- Simulate real-world adversaries and research offensive techniques, evasion methods, and attacker tools.
- Develop scripts, custom tools, and methodologies to improve and automate red team operations.
- Design and test security technologies, automations, and controls.
- Document findings and communicate risks and remediation recommendations to engineering and management teams.
Requirements
- Solid understanding of computer hardware, software, networks, and communications.
- Hands-on experience with Linux/Unix and Windows operating systems, web technologies, SaaS, cloud environments, wireless security, and mobile device security.
- Experience conducting full-scope assessments and penetration tests, including phishing, social engineering, server- and client-side attacks, protocol subversion, and network or web application exploitation.
- Proficiency with scanning, attack, and assessment tools, including at least one C2 framework.
- In-depth knowledge of vulnerabilities such as RCE, SQL injection, SSRF, LFI/path traversal, XXE, insecure deserialization, SSTI, and authentication or authorization flaws.
- Experience modifying exploits or proof-of-concept code, writing technical reports, and working independently and collaboratively.
Nice to have
- 2+ years of experience in red teaming or penetration testing.
- Hands-on offensive security certifications such as OSCP/OSCP+, OSWE, or OSEP.
- Experience developing custom offensive tooling or automation.
- Experience evading EDR or SOC detection in mature, monitored environments.
- Strong written and verbal communication skills in English.
Culture & Benefits
- Full-time employment based in Taipei.
- Work within a global services and cyber threat red team organization.
- Engage in authorized, ethical attack simulations that strengthen customer security resilience.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
1 день назад
Manager, Offensive Security Engineer (Fintech)
1 день назад
Offensive Security Engineer (Fintech)
Wiz
2 дня назад
Threat Detection Researcher (Cybersecurity)
1 день назад
Mobile and Cloud Security Engineer
23 часа назад
Cyber Security Vulnerability Researcher (Linux)
23 часа назад