דרושים » אבטחת מידע וסייבר » Application Penetration Tester

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 9 שעות
דרושים בגב מערכות
מיקום המשרה: הרצליה
סוג משרה: משרה מלאה
תחום אחריות
הובלת מבדקי חדירה מקצה לקצה, זיהוי חולשות אבטחה מורכבות ומתן המלצות לתיקון (Remediation) ברמת הקוד והתשתית.
עבודה שוטפת מול צוותי פיתוח ו- DevOps בסביבות Agile/CI-CD.
דרישות:
ניסיון: 3 שנות ניסיון מעשי לפחות כ- Penetration Tester.
אפליקציות ופיתוח: ניסיון מוכח במבדקי חדירה לאפליקציות Web (SaaS) ומערכות backend מורכבות (כולל רשתות מבודדות), ורקע מעשי בפיתוח ( backend frontend ).
ענן: ניסיון בביצוע מבדקי חדירה לסביבות ענן (AWS, Azure, GCP).
יכולות טכניות: שליטה מוחלטת ב-OWASP Top 10, ביצוע Code Review ידני ( Python, JAVA, C #, JS/ Node.js ), והבנה עמוקה ב-API Security (REST, GraphQL, gRPC) ובפרוטוקולי הזדהות (OAuth2, OIDC, SAML).

יתרון משמעותי
הסמכות: OSCP, OSWE, BSCP, AWS Certified Security או Azure Security Engineer (AZ-500).
AI Security: היכרות עם OWASP Top 10 for LLM (כגון Prompt Injection, Insecure Output Handling) ובחינת עמידות APIs של שירותי AI (OpenAI API, Azure AI Services).
תשתיות ו-Cloud Security: ניסיון באבטחת סביבות Containerized (Kubernetes, Docker), פריצה דרך IAM Roles, Lateral Movement בענן, שליטה ב-Active Directory / Azure AD והתקפות רשת נפוצות. המשרה מיועדת לנשים ולגברים כאחד.
 
הסתר
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8803136
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
1 ימים
דרושים בTOP SOFT טופ סופט - השמה ומיקור חוץ
מיקום המשרה: הרצליה
סוג משרה: משרה מלאה ועבודה היברידית
חפש/ת את האתגר הבא בעולם ה-Offensive Security?

אנחנו מגייסים מומחה/ית Penetration Testing לביצוע מבדקי חדירות אפליקטיביים, תשתיתיים ובענן בסביבה טכנולוגית מתקדמת, עם עבודה צמודה לצוותי פיתוח ותשתיות והשפעה אמיתית על אבטחת המוצרים והמערכות.

מה כולל התפקיד?
ביצוע מבדקי חדירות לאפליקציות Web, Mobile ו-API.
זיהוי חולשות לוגיות וטכניות והערכת סיכונים.
כתיבת דוחות מקצועיים והצגת ממצאים לצוותי פיתוח ותשתיות.
ליווי תהליך תיקון החולשות ומתן המלצות טכנולוגיות.
עבודה עם סביבות Cloud וטכנולוגיות מתקדמות.
דרישות:
לפחות 3 שנות ניסיון מעשי (Hands-on) בביצוע מבדקי חדירות אפליקטיביים.
ניסיון משמעותי עם Burp Suite Professional.
היכרות מעמיקה עם OWASP Top 10 ו-ASVS.
ניסיון בבדיקות API (REST, SOAP, GraphQL) באמצעות Burp או Postman.
יכולת קריאת קוד בשפות כגון JAVA, C #, Node.js או Python.
היכרות עם מנגנוני Authentication ו-Authorization כגון OAuth2, JWT ו-SAML.

יתרון משמעותי
ניסיון בכתיבת סקריפטים ב- Python או Bash.
ניסיון במבדקי חדירות לסביבות Cloud ו-Microservices.
ניסיון בבדיקות Mobile ( Android / IOS ).
היכרות עם Linux, Windows ותקיפות תשתית.
הסמכות כגון OSCP, OSWE או GWAPT. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8755765
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
1 ימים
דרושים ביוניטסק
Job Type: Full Time and Hybrid work
Offensive Security Consultant

We are looking for an Offensive Security Consultant to perform hands-on penetration testing and offensive security assessments for local and global clients. The role covers a wide range of technologies, including Infrastructure, Web Mobile Applications, Red Team, Purple Team, Thick Client and Web3.

What Youll Do:

Perform hands-on Penetration Testing and Offensive Security assessments.
Identify and exploit security vulnerabilities across applications and infrastructure.
Conduct internal and external network assessments.
Work directly with clients to explain findings and support remediation.
Lead engagements from testing and analysis through professional reporting.
Provide practical risk-based security and hardening recommendations.
Requirements:
Requirements
3+ years of hands-on experience in Infrastructure, Networking, system Administration or IT Operations.
1+ year of experience in Offensive Security, including Application and/or Infrastructure Penetration Testing.
Hands-on experience identifying and exploiting security vulnerabilities.
Experience with Burp Suite, Kali Linux, Nmap, Metasploit, Nessus and Wireshark.
Strong communication and technical writing skills.
Ability to work independently and as part of a consulting team.
Advantages
Knowledge of OWASP, PTES or MITRE ATT CK.
Strong TCP/IP and Networking knowledge.
Experience with Active Directory, Windows Domains and Privilege Escalation.
Infrastructure Penetration Testing experience.
Offensive Security certifications.
Experience with Azure, AWS or GCP.
Source Code Review or Database Security experience.
This position is open to all candidates.
 
Show more...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8798482
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Herzliya
Job Type: Full Time
We are looking for a highly skilled and security-savvy Application Security Engineer to lead our product and application security efforts. In this role, you will drive security design, ensure secure coding practices, and validate our services and environments against the highest security standards.

You will work closely with our R&D and Product teams to identify, mitigate, and prevent security risks throughout the software development lifecycle (SDLC). You will own security initiatives, mentor developers on security best practices, and play a key role in shaping the security posture of our products.

The ideal candidate is highly motivated, eager to learn, and has a security by design mindset. This role provides career growth opportunities, enabling you to deepen your expertise in AppSec, DevSecOps, and cloud security.

What you'll do:
Partner with development and product teams to integrate security best practices into the SDLC.
Lead threat modeling and architecture security reviews to proactively identify and mitigate risks.
Conduct security assessments, including code reviews, vulnerability scans, penetration testing, and secure product design reviews.
Stay up to date with emerging security threats, vulnerabilities, and industry trends, ensuring we remains ahead of evolving risks.
Support and contribute to security incident response activities, including root cause analysis and post-incident improvements.
Automate security processes and integrate security tools within CI/CD pipelines.
Develop and deliver secure coding training to engineering teams.
Requirements:
What you have:
3+ years of experience in Application Security, Penetration Testing, or Product Security in a SaaS company
Deep understanding and hands-on experience of web application security, including OWASP Top 10, authentication, encryption, and secure coding principles
Proficiency in scripting or programming languages (Terraform, Python, JavaScript, Go, etc.) for security automation and infrastructure.
Experience with cloud security best practices (AWS, GCP, or Azure)
Strong communication skills, with the ability to explain security risks and recommendations to technical and non-technical stakeholders, including executive management
Experience working with large-scale, complex R&D environments

Bonus Points:
Hands-on experience with DevSecOps and integrating security tools into CI/CD pipelines
Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience)
Being introduced by an AppsFlyer team member
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8788766
סגור
שירות זה פתוח ללקוחות VIP בלבד