远程工作雷达

渗透测试员

Penetration Tester

开发工程限定地区(需当地身份)日间重叠约 2 小时,需偶尔早起或晚睡
公司Terra Security
薪资未公开
工作地点Poland
地域资格限定地区(需当地身份)
时区要求日间重叠约 2 小时,需偶尔早起或晚睡
用工类型Contractor
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 Poland 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:日间重叠约 2 小时,需偶尔早起或晚睡。

描述
Terra Security 提供基于代理的 AI 驱动的持续渗透测试,与代码更改和不断变化的攻击面保持同步,结合经过训练的 AI 代理群与人工监督,以确保安全和控制。财富 500 强企业信任 Terra,在网络、AI、内部应用、API、移动设备、网络和云上确保每个攻击面都得到覆盖。

Terra 正在成为下一个突破性的网络安全公司,目前已筹集 3800 万美元,其中包括由 Felicis Ventures 领投的 3000 万美元 A 轮融资,Dell Technologies Capital、Silicon Valley CISO Investments (SVCI)、SYN Ventures、LAMA Partners、Underscore VC 和 Capital One Ventures 参与投资。

简介
作为渗透测试员,你将成为我们新成立的欧洲渗透测试团队的创始成员。你将在传统伦理黑客技术与前沿 AI 的交汇点工作,提供“人在回路中”的专业知识,确保我们的自主代理始终保持准确、创新且极具效果。这是一个超越标准“检查清单”渗透测试,进入自动化、利用驱动型安全未来的机会。

你将负责

  • 对 Web 应用程序和 API 进行深入渗透测试,识别自动化工具常会忽略的复杂漏洞。
  • 与我们的 AI 代理群协作,提供手动验证、监督和创造性的利用逻辑,以提升平台性能。
  • 研究并开发新的利用技术,使我们的平台始终领先于新兴威胁和独特的业务逻辑风险。
  • 将技术漏洞转化为清晰、高质量的安全报告,为客户提供可操作的修复建议。
  • 为我们在欧洲不断增长的中心的方法论和工作流程做出贡献,与全球团队合作,保持“行业最佳”的测试标准。

要求

  • 在 Web 应用程序和 API 渗透测试方面有 3 年以上实际经验。
  • 对常见的攻击方法、利用技术以及 OWASP Top 10 有深入了解。
  • 熟悉网络协议(TCP/HTTP),并对客户端和服务器端语言有扎实掌握。
  • 精通 Burp Suite、Caido 和其他行业标准的安全测试工具。
  • 能够撰写清晰、专业的安全报告,在技术深度与修复明确性之间取得平衡。
  • 英语水平较高(能流利阅读和书写)
查看英文原文

Description
Terra Security provides agentic AI-powered continuous penetration testing aligned to code changes and evolving attack surfaces, combining a swarm of trained AI agents with human supervision for safety and control. Fortune 500 organizations trust Terra to ensure every attack surface is covered across the web, AI, internal apps, APIs, mobile, networks, and the cloud.
Terra is on track to become the next breakout cybersecurity company with $38 million raised to date, including a $30 million Series A led by Felicis Ventures with participation from Dell Technologies Capital, Silicon Valley CISO Investments (SVCI), SYN Ventures, LAMA Partners, Underscore VC, and Capital One Ventures.
Summary
As a Penetration Tester, you will be a founding member of our new European penetration testing team. You will work at the intersection of traditional ethical hacking and cutting-edge AI, providing the "human-in-the-loop" expertise that ensures our autonomous agents remain accurate, creative, and devastatingly effective. This is an opportunity to move beyond standard "checkbox" pentesting and into the future of automated, exploit-driven security.
What You’ll Do

  • Perform deep-dive penetration tests on Web Applications and APIs, identifying complex vulnerabilities that automated tools often miss.
  • Work alongside our AI agent swarm, providing manual verification, oversight, and creative exploitation logic to enhance the platform’s performance.
  • Research and develop new exploitation techniques to keep our platform ahead of emerging threats and unique business logic risks.
  • Translate technical vulnerabilities into clear, high-quality security reports that provide actionable remediation guidance for our customers.
  • Contribute to the methodologies and workflows of our growing European hub, collaborating with global teams to maintain a "best-in-class" testing standard.

Requirements

  • 3+ years of hands-on experience specifically in Web Application and API Penetration Testing.
  • A strong understanding of common attack methodologies, exploitation techniques, and the OWASP Top 10.
  • Proficiency with networking protocols (TCP/HTTP) and a solid grasp of client-side and server-side languages.
  • Practical expertise with Burp Suite, Caido, and other industry-standard security testing utilities.
  • The ability to write clear, professional security reports that balance technical depth with remediation clarity.
  • High-level English proficiency (fluent in reading, writing, and speaking).

Advantage

  • Experience with Python, Go, or Bash to automate repetitive testing tasks.
  • Holdings such as OSCP, OSWA, OSWE, or equivalent.
  • Familiarity with testing in AWS, Azure, or GCP environments.
  • Interest in or experience with using AI/LLMs to enhance security workflows.

Please note that this position is for candidates based in Poland and is offered as an Independent Contractor (B2B) engagement.
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

渗透测试团队负责人

Terra SecurityPolandContractor今天
开发工程限定地区(需当地身份)日间重叠约 2 小时,需偶尔早起或晚睡

营销活动负责人

Terra SecurityUnited StatesFull Time今天
市场运营限定地区(需当地身份)

品牌设计师

Terra SecurityUnited StatesFull Time今天
设计市场运营限定地区(需当地身份)

← 返回全部职位