إجراء اختبارات اختراق يدوية لتطبيقات الويب وواجهات REST/GraphQL وWebSockets.
تحديد الثغرات المتوافقة مع OWASP Top 10 وOWASP API Security Top 10.
اختبار منطق الأعمال المرتبط بالمالية والتداول، بما في ذلك تManipulation المعاملات، وحالات النسب، عيوب التفويض، وتلاعب الأسعار، والثغرات المرتبطة بالجلسة.
إجراء استغلال الثغرات والتحقق باستخدام Burp Suite وأدوات أمان هجومية أخرى.
تطوير السكريبتات والتقنيات المخصصة لتحديد الثغرات التي قد تفوتها ماسحات الآلة.
تقييم المصادقة والتفويض وإدارة الجلسة والتحقق من الإدخال وأمان API وتدفقات المعاملات.
إنتاج تقارير تفصيلية لاختبار الاختراق مع خطوات قابلة لإعادة الإنتاج وتقييمات المخاطر وتأثير الأعمال وتوصيات تصحيح عملية.
العمل عن كثب مع فرق التطوير وDevSecOps والبنية التحتية للتحقق من إصلاح الثغرات.
إجراء إعادة الاختبار لضمان حل الثغرات المحددة بشكل صحيح.
دعم التحسن المستمر في منهجيات اختبار أمان التطبيق وضوابط الأمن.
ضمان إجراء أنشطة اختبار الأمان بأقل تأثير على أنظمة التداول وعمليات الأعمال.
ملف المرشح المرغوب
درجة البكالوريوس في الأمن السيبراني أو علوم الحاسوب أو تكنولوجيا المعلومات أو مجال ذي صلة.
3+ سنوات من الخبرة العملية في اختبار اختراق تطبيقات الويب وواجهات API.
معرفة عملية قوية بأمان تطبيقات الويب ومنهجيات اختبار الاختراق.
خبرة عملية متقدمة مع Burp Suite وأدوات أمان هجومية شائعة.
فهم قوي لـ OWASP Top 10 وOWASP API Security Top 10 والمصادقة والتفويض وإدارة الجلسة وثغرات منطق الأعمال.
خبرة في اختبار REST APIs وGraphQL وWebSockets وتطبيقات الويب الحديثة.
مهارات برمجة/سكريبتينغ قوية في Python أو JavaScript أو Bash أو لغات مماثلة.
فهم لبيئات AWS و/أو Microsoft Azure وهياكل الخدمات السحابية عبر الويب.
القدرة على إدارة مهام اختبار الاختراق بشكل مستقل من التحديد والاختبار وحتى التقارير والتحقق من الإصلاح.
مهارات تحليلية قوية وحل مشكلات وتقديم تقارير.
Conduct manual penetration testing of web applications, REST/GraphQL APIs, and WebSockets.
Identify vulnerabilities aligned with OWASP Top 10 and OWASP API Security Top 10.
Test financial and trading-specific business logic, including transaction manipulation, race conditions, authorization flaws, price manipulation, and session-related vulnerabilities.
Perform vulnerability exploitation and validation using Burp Suite and other offensive security tools.
Develop custom scripts and techniques to identify vulnerabilities that automated scanners may miss.
Assess authentication, authorization, session management, input validation, API security, and transaction flows.
Produce detailed penetration testing reports with reproducible steps, risk ratings, business impact, and practical remediation recommendations.
Work closely with Development, DevSecOps, and Infrastructure teams to validate vulnerability remediation.
Conduct retesting to ensure identified vulnerabilities have been properly resolved.
Support continuous improvement of application security testing methodologies and security controls.
Ensure security testing activities are conducted with minimal impact on trading systems and business operations.
Desired Candidate Profile
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
3+ years of hands-on experience in web application and API penetration testing.
Strong practical knowledge of web application security and penetration testing methodologies.
Advanced hands-on experience with Burp Suite and common offensive security tools.
Strong understanding of OWASP Top 10, OWASP API Security Top 10, authentication, authorization, session management, and business logic vulnerabilities.
Experience testing REST APIs, GraphQL, WebSockets, and modern web applications.
Strong scripting/programming skills in Python, JavaScript, Bash, or similar languages.
Understanding of AWS and/or Microsoft Azure environments and cloud-based web service architectures.
Ability to independently manage penetration testing engagements from scoping and testing through reporting and remediation validation.
Strong analytical, problem-solving, and reporting skills.
Tanqeeb.com هو محرك البحث عن الوظائف الأول فى الوطن العربى الذى يجمع لك الوظائف المناسبة من مختلف مواقع التوظيف الآخرى فى مكان واحد !