
Divoro — вакансії
- Outsource, Outstaff
- 11-50
- 2013
- Київ, Los Angeles
- CyberSecurity
Актуальні вакансії компанії
Знайдено 3 вакансії
Досвід від 3 років Middle, Senior Full-time Upper-Intermediate / B2 Є тестове завдання Remote
18.10.20247
Детальніше
- SDLC
- Agile
- CI/CD
- Python
- Bash
- Ansible
- Puppet
- Chef
- AWS
- GCP
- Microsoft Azure
- OWASP Top 10
- SAST
- DAST
- SCA
- SIEM
- TLS
- SSL
- IPSEC
- IDS
- IPS
- IaC
We are seeking a skilled and motivated DevSecOps Engineer to join our dynamic team.
Your responsibilities will be:
- Develop and implement security measures throughout the software development lifecycle, including requirements gathering, design, development, testing, and deployment phases.
- Integrate security tools and technologies into the CI/CD pipeline to automate security checks, vulnerability scanning, and code analysis.
- Collaborate with development teams to identify and remediate security vulnerabilities, implementing secure coding practices and providing guidance on secure application design.
- Implement and maintain infrastructure as code (IaC) frameworks, ensuring that security controls and best practices are incorporated into the provisioning and management of cloud resources.
- Perform security assessments and penetration testing on applications and infrastructure to identify vulnerabilities and recommend appropriate remediation measures.
- Monitor and analyze security events and incidents, responding promptly to security breaches and conducting forensic investigations when necessary.
- Develop and enforce security policies, standards, and procedures, ensuring compliance with relevant regulations and industry best practices.
- Stay up to date with the latest security threats, vulnerabilities, and industry trends, and provide recommendations on security enhancements and risk mitigation strategies.
- Collaborate with cross-functional teams to educate and promote security awareness, conducting training sessions and workshops on secure coding practices and security-related topics.
Requirements:
- Excellent verbal and written English skills.
- Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience).
- 3+ years of experience in DevOps, Security Engineering background, knowledge, and/or experience.
- Strong understanding of software development lifecycles (SDLC) and Agile methodologies.
- In-depth knowledge of DevOps practices, tools, and technologies, such as CI/CD pipelines, configuration management, and containerization.
- Proficiency in scripting languages (e.g., Python, Bash) and experience with infrastructure automation tools (e.g., Ansible, Puppet, Chef).
- Familiarity with cloud platforms (e.g., AWS, Azure, GCP) and experience implementing security controls within cloud environments.
- Solid understanding of security principles, industry best practices, and common vulnerabilities (e.g., OWASP Top 10).
- Experience with security scanning tools (e.g., SAST, DAST, SCA), vulnerability management systems, and security information and event management (SIEM) solutions.
- Knowledge of network and system security protocols (e.g., TLS/SSL, IPsec, firewalls, IDS/IPS).
- Excellent problem-solving and analytical skills, with the ability to assess risks, prioritize tasks, and deliver effective security solutions.
- Strong communication and collaboration skills, with the ability to work effectively in cross-functional teams.
Досвід від 2 років Middle Full-time Upper-Intermediate / B2 Є тестове завдання Remote
18.10.20249
Детальніше
- Secure SDLC
- OWASP
- Burp Suite
- SAST
- DAST
- Python
- Bash
We are looking for an AppSec Engineer to join our team.
Your responsibilities will be:
- Perform security assessment and review of code and behaviour of systems.
- Perform risk analysis and threat modelling.
- Assessment, implementation, and development of S-SDLC practices.
- Work with project stakeholders.
- Conducting technical research.
- Advising development teams and other departments on information security issues.
- Conducting reports, workshops, and presentations for training employees.
Requirements:
- Knowledge of OWASP flagship projects.
- At least 2 years of experience in the cybersecurity field.
- Experience in popular security tools required for the job, or ability to learn them quickly (Burp Suite, network analyzers, various SAST and DAST, dependency and vulnerability scanners).
- Experience in performing security assessments for web and/or mobile apps.
- Practical experience in scripting languages: Python or Bash.
- Understanding the secure software development life cycle.
- Communication skills: you will communicate about security technical topics with both technical and non-technical audiences (C-level managers, developers, product owners).
Досвід від 3 років Senior Full-time Upper-Intermediate / B2 Є тестове завдання Remote
18.10.202411
Детальніше
- Metasploit
- Burp Suite
- nmap
- Wireshark
- Python
- Bash
- PowerShell
- PCI DSS
- ISO 27001
We are looking for Senior Penetration Tester to join our team. As a Senior Penetration Tester, your primary responsibility will be to conduct advanced security assessments and penetration testing engagements to identify vulnerabilities and weaknesses in the organization's infrastructure, applications, and systems. Your role will also involve creating comprehensive reports and recommending appropriate remediation measures to mitigate identified risks.
Your responsibilities will be:
- Conduct comprehensive penetration tests on systems, networks, and applications to identify vulnerabilities, weaknesses, and potential security risks. Utilize various tools, techniques, and methodologies to simulate real-world attacks and gain unauthorized access to systems for testing purposes.
- Perform vulnerability assessments to identify and categorize vulnerabilities in systems and applications. Use scanning tools and manual techniques to discover known security weaknesses and misconfigurations.
- Exploit identified vulnerabilities to gain unauthorized access and evaluate the potential impact of a successful attack. Conduct further investigations to determine the extent of the compromise, potential data exfiltration, and potential lateral movement within the network.
- Document and communicate the findings, vulnerabilities, and recommended remediation measures in a clear and concise report. Provide stakeholders with detailed technical descriptions, risk ratings, and mitigation strategies, including technical teams and management.
- Advise stakeholders on security best practices, potential risks, and recommended security controls. Collaborate with system administrators, developers, and other stakeholders to assist in implementing necessary security measures.
- Stay current with security vulnerabilities, attack techniques, and industry trends. Continuously enhance your knowledge and skills by conducting research, participating in relevant communities, and attending training or conferences.
- Work collaboratively with cross-functional teams to ensure effective communication and coordination during penetration testing engagements. Clearly communicate technical concepts, risks, and mitigation strategies to technical and non-technical stakeholders.
- Stay informed about relevant compliance requirements and industry standards (e.g., PCI DSS, HIPAA, ISO 27001). Ensure that penetration testing activities align with these standards and regulatory frameworks.
Qualifications:
- Bachelor's degree in Computer Science, Information Security, or a related field.
- Proven experience conducting penetration testing engagements, including network, web application, and wireless assessments.
- Strong understanding of networking protocols, operating systems, and web technologies.
- Familiarity with penetration testing tools like Metasploit, Burp Suite, Nmap, Wireshark, etc.
- Knowledge of scripting languages (e.g., Python, PowerShell, Bash) for automation and custom tool development.
- Excellent verbal and written English skills.
- Analytical and problem-solving skills, with the ability to identify and exploit vulnerabilities effectively.
- Great written and verbal communication skills to convey technical concepts and findings to stakeholders.
- Familiarity with compliance standards (e.g., PCI DSS, HIPAA, ISO 27001) and industry regulations is beneficial.
- Strong ethical standards and adherence to professional conduct in handling sensitive information and conducting penetration tests.
- Ability to work both independently and collaboratively in a team environment.
- Continuous learning mindset to keep up with emerging security threats, vulnerabilities, and mitigation techniques.
Переваги для співробітників Divoro
- Гнучкий графік роботи
- Компенсація навчання
- Медичне страхування
- Оплачувані лікарняні
- Оплачувана відпустка
Читайте нас в Telegram, щоб не пропустити анонси нових вакансій.