Назад
Company hidden
3 дня назад

Penetration Tester, Web/Mobile Apps and Cloud Services (Cybersecurity)

80 000 - 132 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Penetration Tester, Web/Mobile Apps and Cloud Services (Cybersecurity): Testing cloud services, web applications, and APIs while assessing cloud configurations, threats, and incident response with an accent on vulnerability discovery, security automation, and CI/CD integration. Focus on identifying OWASP Top 10 risks, analyzing SAST results, developing penetration-testing tools, and improving cloud security controls.

Location: On-site in Irvine, California, United States

Salary: $80,000–$132,000 per year

Company

hirify.global Systems develops networking devices, smart home products, and cloud services for customers in more than 170 countries.

What you will do

  • Perform penetration testing of cloud services, web applications, and APIs, then document vulnerabilities and remediation recommendations.
  • Conduct threat modeling and security assessments for defined cloud components and web application modules.
  • Support cloud and web application incident response, including investigation, containment, remediation, and post-incident analysis.
  • Analyze cloud security configurations and identify vulnerabilities caused by misconfigurations.
  • Help develop penetration-testing tools, automated testing platforms, and scripts for cloud environments.
  • Contribute to CI/CD security processes and the implementation of cloud security standards and regulatory requirements.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • 1–3 years of experience as a Security Engineer or in a similar cloud and web security role.
  • Strong knowledge of web application security, cloud security, API security, and the OWASP Top 10.
  • Experience with tools such as Burp Suite, OWASP ZAP, Nmap, Kali, Nessus, and Metasploit.
  • Proficiency in at least one programming language, such as Python, JavaScript, Bash, or PowerShell, and familiarity with AWS, Azure, or GCP security controls.
  • Ability to analyze SAST results, identify false positives, optimize testing automation, communicate effectively, and collaborate with cross-functional teams.

Nice to have

  • Security certifications such as CEH or OSWP.
  • Published CVEs.

Culture & Benefits

  • Fully paid medical, dental, and vision insurance, with partial dependent coverage.
  • Employer quarterly contributions to 401(k) funds.
  • 15 accrued vacation days and 11 paid holidays.
  • Bi-annual performance reviews and annual pay increases.
  • Health and wellness benefits, including a free gym membership, plus quarterly team-building events.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →