۱ ساعت پیش
استخدام Senior Security Engineer برای دیجی کالا در تهران
حضوری
مقطع تحصیلی اعلام نشده
سابقه دارد (۵ تا ۹ سال)
حقوق توافقی
آقا و خانم
تمام وقت
مشاهده اطلاعات تماس
اطلاعات بیشتر
امروز
دیجی کالا در تهران (ونک) جهت تکمیل کادر خود به افراد واجد شرایط ذیل نیازمند است.
| Description | job title |
| Over View: The Senior Security Engineer is part of Digikala’s Offensive Security team and is responsible for identifying and reducing security risks across web applications, APIs, and supporting services. The role exists to detect vulnerabilities before they can be exploited, support secure product delivery, and help development teams remediate security issues effectively. This position works closely with Development, DevOps, Cloud, SOC, Infrastructure, and Product teams. Responsibilities Perform comprehensive black-box, grey-box, and white-box penetration testing of web applications, APIs, microservices, and internal services. Identify high-impact vulnerabilities, including authentication bypass, authorization issues, IDOR, SSRF, injection flaws, business logic weaknesses, and sensitive data exposure. Complete assigned security assessments within agreed timelines and provide clear, reproducible, and risk-based reports. Validate remediation actions and ensure that critical and high-severity vulnerabilities are properly resolved before production deployment. Support DevSecOps processes by reviewing findings from SAST, DAST, secret scanning, dependency scanning, and container security tools. Conduct threat hunting activities for exposed assets, vulnerable services, leaked credentials, public repositories, and newly published CVEs. Provide practical remediation guidance and work directly with engineering teams to reduce security risks. Improve penetration-testing methodologies, automation scripts, security rules, and internal technical documentation. Requirements: At least five years of professional experience in penetration testing, application security, or offensive security. Advanced knowledge of web application and API security. Strong understanding of OWASP Top 10 and OWASP API Security Top 10. Hands-on experience with REST APIs, GraphQL, authentication, authorization, OAuth 2.0, OpenID Connect, JWT, and session management. Strong experience identifying complex business logic and access-control vulnerabilities. Proficiency with tools such as Burp Suite Professional, Nmap, Nuclei, OWASP ZAP, and Wireshark. Knowledge of Linux, Docker, Kubernetes, cloud environments, and CI/CD pipelines. Familiarity with DevSecOps tools such as Semgrep, Gitleaks, Trivy, DefectDojo, and dependency-scanning solutions. Ability to develop security automation using Bash, Go, or similar languages. Strong analytical thinking, problem-solving, and attention to detail. Ability to assess technical findings based on exploitability and business impact. Strong technical reporting and documentation skills. Effective communication and teamwork across technical and non-technical teams. Ability to work independently, manage multiple assessments, and take ownership of security risks. Ability to mentor junior security engineers and review penetration-testing results. Certifications such as OSCP, OSWE, OSEP, BSCP, or similar are preferred but not mandat |
Senior Security Engineer |
متقاضیان واجد شرایط می توانند با کلیک روی لینک تکمیل فرم استخدام، رزومه خود را ارسال نمایند.
اطلاعات تماس
گزارش مشکل آگهی
- ثبتنام برای تکمیل فرم استخدام اینجا کلیک نمایید
- مهلت ۱۴۰۵/۰۷/۱۲
آگهیهای مشابه
جستجوهای مشابه
- استخدام مهندس IT در شهر تهران
- استخدام مهندس IT در استان تهران
- استخدام مدیر سرور در استان تهران
- استخدام کارشناس شبکه در شهر تهران
- استخدام رشته کامپیوتر در شهر تهران
- استخدام مهندس نرم افزار در شهر تهران
- استخدام مهندس کامپیوتر در استان تهران
- استخدام رشته کامپیوتر در استان تهران
- استخدام رشته فناوری اطلاعات (IT) در شهر تهران
- استخدام رشته فناوری اطلاعات (IT) در استان تهران
دستهبندی آگهیهای استخدام