高级渗透测试员(网页和API),合同制
Senior Penetration Tester (Web and API), Contract
Invadel 是一家位于纽约市的渗透测试公司。每次服务都是固定范围和固定价格,以书面形式确认,公开价格见 invadel.com/pricing,并提供免费的重新测试。这是一个合同职位,远程办公,仅限美国境内,按项目付费;一次典型的服务包括五到十天的测试时间加上一次重新测试,时间安排根据您的可用性而定
您将负责:在每个用户角色(授权、认证和会话、注入、业务逻辑、SSRF、文件处理和反序列化)中领导手动 Web 应用和 API 渗透测试;手动验证或排除每个自动化结果,并将发现的问题串联起来以安全地证明影响;在确认关键问题的当天进行升级;撰写报告(执行摘要、包含复现步骤和 CVSS 分数的问题、优先修复建议、框架映射);对已修复的问题进行重新测试
我们需要:五年或以上实际应用渗透测试经验,主要集中在 Web 和 API;至少熟悉一种现代技术栈(单页应用、GraphQL、OAuth 和 OIDC、多租户 SaaS);在美国居住并拥有在此工作的合法资格;能为工程师和审计人员撰写报告,申请时需附上一份脱敏的报告样本;两位专业推荐人
加分项:具备移动设备(MASVS 和 MASTG)或 AWS、Azure 或 GCP 上的云测试经验;有发表的研究、工具或披露的漏洞。拥有进攻性安全认证是欢迎的,但不会替代可验证的项目记录
完整描述、薪资范围和申请方式:
最初发布于 Himalayas
查看英文原文
Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; a typical engagement is five to ten testing days plus a retest, scheduled around your availability.
What you will do: lead manual web application and API penetration tests across every user role (authorization, authentication and sessions, injection, business logic, SSRF, file handling and deserialization); confirm or discard every automated result by hand and chain findings to prove impact safely; escalate critical findings the day they are confirmed; write the report (executive summary, findings with reproduction steps and CVSS scores, prioritized remediation, framework mapping); retest remediated findings.
What we need: five or more years of hands-on application penetration testing, mostly web and API; depth on at least one modern stack (single-page applications, GraphQL, OAuth and OIDC, multi-tenant SaaS); based in the United States with authorization to work here; reports written for engineers and auditors, with a redacted sample report as part of the application; two professional references.
Nice to have: mobile (MASVS and MASTG) or cloud testing on AWS, Azure or GCP; published research, tooling or disclosed vulnerabilities. An offensive security certification is welcome; it does not replace a verifiable engagement record.
Full description, pay range and application:
Originally posted on Himalayas