Security Technologist - Sao Paulo, Brasil - Uber

Uber
Uber
Empresa verificada
Sao Paulo, Brasil

há 1 mês

Ana Silva

Postado por:

Ana Silva

beBee Recruiter


Descrição
Conduct network infrastructure, Public Cloud (AWS and GCP), and data-layer offensive pen-testing

  • Perform manual source code reviews and audits (manual and SCA/SAST code audits) as needed
  • Basic Qualifications
  • A pentest certification such as Offensive Security Certified Professional (OSCP) or CEH, OSWE, OSCE, GPEN, GMOB, GWAPT, GXPN, eWAPT, eMAPT and/or willing to work towards ultimately obtaining one as part of your career path
  • 3+ years of relevant engineering or security assessment experience
  • Possess a broad knowledge of attack vectors, exploits and mitigations that work at scale or may be linked together for chained attacks
  • Experience with assessing with Cloudnative services, service meshes, and Kubernetesplatform based microservices
  • Be able to think both offensively (like a hacker) and defensively (evaluating product security and design)
  • Ability to create written work product, detailed technical findings documents, and pentest reports
  • Ability to create and write scripts to automate redundant activities
  • Great interpersonal skills, deep technical ability, and a history of successful execution in the assessments industry. If you enjoy discussing anything from procedural linking tables in kernels to remote code execution in JVMs, then we want you on the team
  • Experience with Java, Go, Python or (bonus points for more than one)
  • Familiarity with industrystandard threat modeling, risk modeling and vulnerability classification.
  • Experience with preassessment architectural and API analysis to scope and prepare whitebox and greybox assessments.
  • Experience working with inhouse engineering organizations, S-SDLC/CICD software lifecycle and QA processes.
  • Experience with mobile reverse engineering and penetration testing.
  • Experience with CLI offensive security tooling.

Mais empregos da Uber