Senior Security Engineer – Red Team

Posted 5hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Red-team security engineer conducting penetration tests and threat research for Insider One’s AI-powered marketing and customer engagement platform. Supporting secure development across agile teams.

Responsibilities:

  • Perform web, mobile application, and internal penetration tests
  • Conduct source-code reviews, threat analysis, and social-engineering assessments
  • Support blue teams when needed
  • Research new attack vectors and stay current with cybersecurity news and trends
  • Train Quality Assurance and Development teams in security testing techniques and secure software development
  • Support developers in business units throughout the SDLC
  • Provide guidance on mitigations for emerging threats
  • Review application source code using static application security testing tools
  • Conduct security research on vulnerabilities and testing tools
  • Create detailed documentation and reports communicating vulnerabilities, mitigation strategies, and remediation steps
  • Execute white-, gray-, or black-box security posture assessments
  • Collaborate with agile teams and other departments

Requirements:

  • 4+ years of working experience in web application security
  • Hands-on experience testing web applications, web services, mobile applications, and APIs
  • Experience securing REST APIs and web services
  • Experience using and implementing SAST/DAST tools such as Fortify, Veracode, or Checkmarx
  • Knowledge of penetration testing information systems using commercial and open-source exploitation tools
  • Understanding of standard security vulnerabilities and remediation based on OWASP, SANS, and similar standards
  • Experience with secure coding methodologies and implementation within engineering teams
  • Ability to support developers throughout the SDLC and guide mitigations for emerging threats
  • Experience reviewing application source code using static application security testing tools
  • Security research experience involving vulnerabilities and testing tools
  • Ability to create detailed vulnerability, mitigation, and remediation reports
  • Ability to work on multiple projects concurrently
  • Strong written and verbal communication skills in English
  • Python, JavaScript, or PHP programming experience is a plus
  • Scripting and automation-script experience for application security testing is a plus
  • Familiarity with cloud security, particularly AWS security concepts, is a plus
  • Certifications such as eWAPTx, OSCP, or OSWE are a plus
  • Ability to work in a team-centric environment
  • Strong critical-thinking and analytical skills
  • Experience executing white-, gray-, or black-box security posture assessments and producing detailed reports

Benefits:

  • Monthly meal allowance
  • Comprehensive private health insurance
  • Access to Spotify, LinkedIn Learning, Blinkist, MasterClass, Neoskola, and CloudGuru
  • Internal training covering AI fundamentals, coding, foreign languages, and personal development skills
  • Diverse global team environment
  • Eligibility-based ESOP/share ownership
  • Referral bonuses
  • Volunteering and purpose-driven social impact projects
  • Global retreats and team-building activities
  • Tech & Dev Talks and industry events
  • Fully remote work from anywhere in Turkey