VARITE INC · 20 hours ago
USA_Senior Security Engineer
VARITE INC is a company specializing in security solutions, and they are seeking a Senior Security Engineer. The role involves conducting security testing, providing consultative guidance on vulnerabilities, and supporting clients in enhancing their security posture through various penetration testing activities.
Information Technology & Services
Responsibilities
Assisting in technical scoping of security testing activities
Curation and assessment of vulnerability data (across multiple platforms/tools) from a manual penetration perspective, to focus on true exploitation
Conducting focused research when not deployed on an active project
Provide consultative guidance to customers on findings identified in a clear and actionable fashion both in writing and verbally
Architecture Security Analyzing and Threat Modeling as required
Curation and assessment of vulnerability data (across multiple platforms/tools) from a code assessment perspective, to ensure false positive review and analysis to provide target results to customers
Provide technical guidance in supporting member firms in conducting necessary remedial actions and responding to client vulnerability questions or disclosures
Help develop tooling deployment and relevant scanning configurations to enhance practical testing processes
Escalates key risks and issues to the relevant Regional Operations Manager which need special attention or hold urgency
Operate in the wider organization to drive risk reduction goals and in the continuous improvement vulnerability related services
As needed to meet customer requests support code assessment and network infrastructure
Typical security testing activities:
Software/Web Application/Web Services penetration testing
Network Penetration Testing
Mobile Application Penetration Testing
Thick Client Penetration Testing
Knows scripting language
Review test cases from time to time
Automated tools like Burp Suite
Qualification
Required
Minimum Experience – 6 to 8 years
Curation and assessment of vulnerability data (across multiple platforms/tools) from a manual penetration perspective, to focus on true exploitation
Conducting focused research when not deployed on an active project
Provide consultative guidance to customers on findings identified in a clear and actionable fashion both in writing and verbally
Architecture Security Analyzing and Threat Modeling as required
Curation and assessment of vulnerability data (across multiple platforms/tools) from a code assessment perspective, to ensure false positive review and analysis to provide target results to customers
Provide technical guidance in supporting member firms in conducting necessary remedial actions and responding to client vulnerability questions or disclosures
Help develop tooling deployment and relevant scanning configurations to enhance practical testing processes
Escalates key risks and issues to the relevant Regional Operations Manager which need special attention or hold urgency
Operate in the wider organization to drive risk reduction goals and in the continuous improvement vulnerability related services
Support code assessment and network infrastructure as needed to meet customer requests
Typical security testing activities: Software/Web Application/Web Services penetration testing, network Penetration Testing, Mobile Application Penetration Testing, Thick Client Penetration Testing
Knows scripting language
Review test cases from time to time
Automated tools like Burp Suite
Skills: Vulnerability Assessment and Penetration Testing
Preferred
Preferred Certification – CISSP, OSCP/CPT/CEPT/ CMWAPT