Information Security Engineer III
- Penetration Testing
- Android
- iOS
- Active Directory
- WAF
- EDR
- SIEM
- IAM
- Network Security
- Incident Response
- OWASP
- GraphQL
- OAuth
- JWT
- SSL
- Windows
- Linux
- Burp Suite
- Nmap
- Metasploit
- Wireshark
- Nessus
- Python
- Bash
- PowerShell
- AWS
- Azure
- GCP
- Bug Bounty
Responsibilities:
·Conduct in-depth penetration testing of Web, Mobile (Android/iOS), API, and Internal, External infrastructure penetration testing
·Perform vulnerability assessments, exploitation, privilege escalation, lateral movement, and attack-path analysis.
·Conduct Active Directory, network, cloud, and application security testing.
·Execute Attack & Breach Simulation (BAS) and adversary emulation using the MITRE ATT&CK framework.
·Plan and execute Red Team exercises simulating real-world threat actors.
·Conduct Purple Team exercises with Blue/SOC teams to validate detection and response capabilities.
·Assess and validate security controls including WAF, EDR/XDR, SIEM, IDS/IPS, IAM, and network security controls.
·Work with Blue/SOC teams to improve detection rules, logging, threat hunting, and incident-response capabilities.
·Prepare technical and executive-level reports, risk ratings, remediation recommendations, and remediation validation.
·Provide detailed security assessment reports and work with development/IT teams to implement fixes.
·Stay updated with the latest threats, vulnerabilities, CVE’s and hacking techniques.
TechnicalSkillsRequired:
·3+ years of experience in penetration testing, ethical hacking, or offensive security.
·Strong knowledge of security testing methodologies, tools, and frameworks.
·Web: OWASP Top 10, Business Logic, Authentication & Authorization.
·API: REST, GraphQL, OAuth, JWT, BOLA/IDOR.
·Mobile: Android/iOS, Frida, MobSF, otool, Objection, Reverse Engineering, SSL Key Pinning Bypass.
·Red/Purple Teaming & MITRE ATT&CK.
·Infrastructure: Network, Active Directory, Windows/Linux, Cloud.
·Tools: Burp Suite, Nmap, Metasploit, SQLMap, BloodHound, Impacket, Wireshark, Nessus, ffuf, Amass.
·Hands-on experience with manual and automated security testing techniques.
·Proficiency in scripting languages such as Python, Bash, or PowerShell.
·Experience with cloud security (AWS, Azure, GCP) is a plus.
·Bug Bounty / Vulnerability Research experience is a plus.
·Familiarity with secure coding practices and application security.
·Scripting: Python, PowerShell, Bash.
Information Security Engineer III · 7-Eleven