Cyversity

Security Engineer - Red Team

Spotlight Preferred
Netskope
St. Louis, Missouri, United States (on-site)
14 days ago

Description

Netskope's Global Information Security organization is looking for a security engineer to be a part of Redteam and offensive security operations. This position will be responsible for assessing Netskope products and cloud services from a holistic security perspective. A successful candidate should have strong offensive technical skill sets and can identify and provide recommendations for security vulnerabilities pertaining to varying technologies and environments.

Responsibilities:

  • Act as a SME for offensive security technical areas
  • Perform comprehensive security assessment of, but not limited to, web & mobile applications, containers, k8s, thick client, cloud environments
  • Perform triage and implement SAST, DAST and SCA process
  • Support junior team members in their authoring of reports and issues
  • Support and recreate proofs of concept from security reports
  • Support and be a member of the PSIRT organization
  • Automate day-to-day red team tasks


Requirements

  • 6+ years of penetration testing, application security, red team experience in highly diversified and high growth organizations.
  • Understanding of application frameworks and how to approach security as well as security pitfalls with them
  • Proven expertise in web and mobile application penetration testing (Web, Mobile, API/Web Services) - DAST and SAST
  • Should have experience with tools Burp suite professional, Metasploit, Tenable, SQL Map and Nmap
  • Have experience in developing exploits and tooling from vulnerabilities both pre and post exploitation and lateral movement
  • In-depth knowledge of OWASP Web and Mobile Top 10 vulnerabilities, identifying, exploiting, and remedidating them
  • Good knowledge of TCP/IP and other application and network level protocols
  • Be able to author and issue reports on assigned application and system scan
  • Good exposure to cloud service providers like AWS, GCP and other SaaS applications
  • Experience in automating security tasks using Python or any other scripting language
  • Should be able to think "Out of the box". Possess ability to think and implement new attack approaches/vectors
  • Should possess relevant university degree and/or professional qualifications/certification (e.g. CEH, OSCP, CISSP)
  • Be able to support the development of tooling for CI/CD/CS processes enabling other teams to test their own systems and work output
  • Excellent written and verbal communication skills.
  • Self-motivated, curious, knowledgeable pertaining to news and current events

Netskope respects your privacy and is committed to protecting the personal information you share with us, please refer to Netskope's Privacy Policy for more details.

Job Information

  • Job ID: 68155090
  • Workplace Type: On-Site
  • Location:
    St. Louis, Missouri, United States
  • Company Name For Job: Netskope
  • Position Title: Security Engineer - Red Team
  • Job Function: Security Engineer
  • Job Type: Full-Time
  • Job Duration: Indefinite
  • Min Experience: 5-7 Years

Please refer to the company's website or job descriptions to learn more about them.

View Full Profile

Jobs You May Like