Penetration Tester
Il y a 16 heures
Strasbourg, Grand Est, France
Response Informatics
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
Greetings from Response Informatics
We are currently hiring a Security/Penetration Test Engineer for an exciting client engagement.
Role: Security/Penetration Test Engineer
Location:
Strasbourg, France (Onsite every day at the office) Position: Contract Language : Fluent English Please Note: Due to security clearance requirements, we can only consider EU Citizens for this position Must work 5 days a week from the end customer's office in Strasbourg, France Description We currently have a vacancy for a Security/Penetration Test Engineer fluent in English, to offer his/her services as an expert who will be based in France. The work will be carried out either into the company’s premises or on site at customer premises. In the context of the first assignment, the successful candidate will be integrated in the Development team of the company that will closely cooperate with a major client’s IT team. Tasks:
• Identify, analyse and assess technical and organisational cybersecurity vulnerabilities;
• Identify attack vectors, uncover and demonstrate exploitation of technical cybersecurity vulnerabilities;
• Test systems and operations compliance with regulatory standards;
• Select and develop appropriate penetration testing techniques;
• Organise test plans and procedures for penetration testing;
• Establish procedures for penetration testing result analysis and reporting;
• Document and report penetration testing results to stakeholders;
• Deploy penetration testing tools and test programs;
• Security source code review or development experience at least in C/C++, C#, VB.
NET, ASP, or Java;
• Identify the security risk level, business impact and provide the remediation plan;
• Use tools and manual testing to perform code security analysts to identify vulnerabilities and attack vectors in applications and infrastructure. Execute SAST, DAST, vulnerability scans and penetration tests;
• Draft security test cases based on the requirements. Requirements
• University degree in IT combined with relevant professional experience of at least 7 years in providing IT and Information security services;
• Experience with penetration testing against a wide variety of applications including web, mobile, and thick client above and beyond running automated tools required;
• Experience providing consulting services in a highly confidential environment;
• Experience with SAST: SonarQube, OWASP, FortifySCA, NVD;
• Experience with DAST, Web Application and Penetration Tests: Fortify WebInspect, OWASP ZAP, Burp Suite, Kali Linux;
• Experience with dependencies and containers tests: GitHub Advanced Security, JFrog XRay, JFrog Curation, Advanced Cluster Security;
• Experience in technical analysis, reporting and writing documents;
• Experience in decomposing and analysing systems to identify weaknesses and ineffective controls;
• Experience in reviewing codes assess their security;
• Industry certifications or similar qualifications appropriate to the services provided, such those listed below, will be considered a plus: GIAC Certified Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), Certified Ethical Hacker (CEH), GIAC Systems and Network Auditor (GSNA), Certified Penetration Tester (CPT), Certified Expert Penetration Tester (CEPT), GIAC Certified Web Application Defender (GWEB), ISC2 Certified Secure Software Lifecycle Professional (CSSLP), Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), CREST Penetration Testing Certifications.
• Excellent command of the English language
Location:
Strasbourg, France (Onsite every day at the office) Position: Contract Language : Fluent English Please Note: Due to security clearance requirements, we can only consider EU Citizens for this position Must work 5 days a week from the end customer's office in Strasbourg, France Description We currently have a vacancy for a Security/Penetration Test Engineer fluent in English, to offer his/her services as an expert who will be based in France. The work will be carried out either into the company’s premises or on site at customer premises. In the context of the first assignment, the successful candidate will be integrated in the Development team of the company that will closely cooperate with a major client’s IT team. Tasks:
• Identify, analyse and assess technical and organisational cybersecurity vulnerabilities;
• Identify attack vectors, uncover and demonstrate exploitation of technical cybersecurity vulnerabilities;
• Test systems and operations compliance with regulatory standards;
• Select and develop appropriate penetration testing techniques;
• Organise test plans and procedures for penetration testing;
• Establish procedures for penetration testing result analysis and reporting;
• Document and report penetration testing results to stakeholders;
• Deploy penetration testing tools and test programs;
• Security source code review or development experience at least in C/C++, C#, VB.
NET, ASP, or Java;
• Identify the security risk level, business impact and provide the remediation plan;
• Use tools and manual testing to perform code security analysts to identify vulnerabilities and attack vectors in applications and infrastructure. Execute SAST, DAST, vulnerability scans and penetration tests;
• Draft security test cases based on the requirements. Requirements
• University degree in IT combined with relevant professional experience of at least 7 years in providing IT and Information security services;
• Experience with penetration testing against a wide variety of applications including web, mobile, and thick client above and beyond running automated tools required;
• Experience providing consulting services in a highly confidential environment;
• Experience with SAST: SonarQube, OWASP, FortifySCA, NVD;
• Experience with DAST, Web Application and Penetration Tests: Fortify WebInspect, OWASP ZAP, Burp Suite, Kali Linux;
• Experience with dependencies and containers tests: GitHub Advanced Security, JFrog XRay, JFrog Curation, Advanced Cluster Security;
• Experience in technical analysis, reporting and writing documents;
• Experience in decomposing and analysing systems to identify weaknesses and ineffective controls;
• Experience in reviewing codes assess their security;
• Industry certifications or similar qualifications appropriate to the services provided, such those listed below, will be considered a plus: GIAC Certified Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), Certified Ethical Hacker (CEH), GIAC Systems and Network Auditor (GSNA), Certified Penetration Tester (CPT), Certified Expert Penetration Tester (CEPT), GIAC Certified Web Application Defender (GWEB), ISC2 Certified Secure Software Lifecycle Professional (CSSLP), Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), CREST Penetration Testing Certifications.
• Excellent command of the English language