TP-Link · 1 day ago
Penetration Tester, Web/Mobile Apps and Cloud Services
TP-Link Systems Inc. is a global provider of reliable networking devices and smart home products, committed to delivering innovative products that enhance connectivity. They are seeking a skilled and proactive Penetration Tester to support cloud service projects, focusing on penetration testing, threat modeling, and security assessments to enhance the security of their cloud services.
Consumer Electronics
Responsibilities
Perform penetration testing on cloud services, web applications, and APIs to identify vulnerabilities. Provide remediation recommendations and write detailed penetration test reports
Perform threat modeling to identify and evaluate potential risks for specific cloud components and web applications
Support cloud and web application incident response, including investigation, containment, remediation, and post-incident analysis. Coordinate with cross-functional teams to ensure effective resolution
Analyze cloud security configurations and identify misconfigurations that could lead to vulnerabilities
Assist in developing various pen-testing tools, automated testing platforms, and scripts to enhance testing efficiency and accuracy for cloud environments
Participate in the development and improvement of the company's CI/CD security processes, ensuring security considerations are integrated throughout the development lifecycle
Interpret cloud security standards and regulatory requirements, supporting implementation of security requirements
Qualification
Required
Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent work experience)
Proven 1-3 years experience as a Security Engineer (Cloud & Web) or in a similar role
Strong knowledge of web application security, cloud security concepts, API security, and common vulnerabilities (OWASP Top 10)
Experience with security tools such as Burp Suite, OWASP ZAP, Nmap, Kali, Nessus, Metasploit, etc
Capability to optimize penetration testing tools and automation strategies for cloud environments
Ability to analyze SAST results and identify false positives
Proficient in at least one programming language (e.g., Python, JavaScript, Bash, or PowerShell)
Familiarity with major cloud platforms (AWS, Azure, GCP) and their security controls
Preferred
Relevant security certifications (e.g., CEH, OSWP, etc.) are highly preferred
Published CVEs are highly preferred
Benefits
Free snacks and drinks, and provided lunch on Fridays
Fully paid medical, dental, and vision insurance (partial coverage for dependents)
Contributions to 401k funds
Bi-annual reviews, and annual pay increases
Health and wellness benefits, including free gym membership
Quarterly team-building events
Company
TP-Link
Headquartered in the United States, TP-Link is a global provider of reliable networking devices and smart home products, consistently ranked as the world’s top provider of Wi-Fi devices.
Funding
Current Stage
Late StageCompany data provided by crunchbase