وصف الوظيفة
الأدوار والمسؤوليات
وصف الوظيفة
كجزء من تعزيز فريق الأمن السيبراني لدينا، أكتب إليكم بخصوص فتح باب وظيفي لمختبر اختراق أول/مراجع شفرة المصدر.
سيشمل هذا الدور إجراء تقييمات أمنية على التطبيقات والبنية التحتية وبيئات Active Directory.
المهام الرئيسية:
- إجراء اختبارات اختراق خارجية وداخلية على البنية التحتية والشبكات ونُظم المعلومات.
- إجراء تدقيقات أمنية في بيئات Active Directory (تحديد ثغرات التكوين، وأخطاء التفويض، ومسارات تصعيد الامتيازات، ومخاطر الاختراق).
- إجراء تدقيقات شفرة المصدر لتحديد الثغرات، وعيوب التصميم، وانحرافات عن أفضل ممارسات التطوير الآمن.
- إجراء تدقيقات أمنية لتطبيقات الويب وواجهات برمجة التطبيقات والخدمات المكشوفة.
- تحليل المخاطر وتقييم تأثيرها وتقديم التوصيات التقنية والتنظيمية المناسبة.
- كتابة تقارير فنية وملخصات تنفيذية تعرض الثغرات وإجراءات التصحيح.
- عرض نتائج التدقيق للفِرق الفنية ودعم تنفيذ خطط التصحيح.
- لضمان الرصد الفني والمساهمة في التحسين المستمر لمنهجيات التدقيق واختبار الاختراق.
المرشح المطلوب
المؤهلات
- درجة Bac+5 في الأمن أو مؤهل مكافئ.
- خبرة لا تقل عن 4 سنوات في اختبارات الاختراق والتدقيق الأمني.
- خبرة قوية في الاختراقات الخارجية والداخلية.
- إتقان بيئات Microsoft Active Directory وقضايا الأمان المرتبطة.
- خبرة مثبتة في تدقيق شفرة المصدر وتحليل أمان التطبيقات.
- معرفة جيدة بمنهجيات اختبارات الاختراق ومعايير أمان التطبيق وأفضل ممارسات التطوير الآمن.
- مهارات تحليلية قوية، وكتابة تقارير واتصالات ممتازة.
- الشهادات المطلوبة: OSCP、OSWE、OSEP أو CRTE.
- اتصال جيد بالفرنسية والإنجليزية.
Job Description
Roles & Responsibilities
Job Description
As part of strengthening our Cybersecurity team, I am writing to you regarding a job opening for a Senior Pentester/Source Code Auditor.
This role will involve conducting security assessments on applications, infrastructure, and Active Directory environments.
Main tasks:
- Conduct external and internal penetration tests on infrastructure, networks, and information systems.
- Conduct security audits of Active Directory environments (identifying configuration weaknesses, delegation errors, privilege escalation paths, and risks of compromise).
- Perform source code audits to identify vulnerabilities, design flaws, and deviations from secure development best practices.
- Conduct security audits of web applications, APIs, and exposed services.
- Analyze risks, assess their impact, and propose appropriate technical and organizational recommendations.
- Write technical reports and executive summaries presenting vulnerabilities and corrective measures.
- Present audit results to technical teams and support the implementation of remediation plans.
- To ensure technical monitoring and contribute to the continuous improvement of audit and penetration testing methodologies.
Desired Candidate Profile
Qualifications
- Bac+5 degree in security or equivalent qualification.
- Minimum 4 years of experience in penetration testing and security auditing.
- Solid experience in external and internal penetration testing.
- Proficiency in Microsoft Active Directory environments and associated security issues.
- Proven experience in source code auditing and application security analysis.
- Good knowledge of penetration testing methodologies, application security standards and secure development best practices.
- Excellent analytical, report writing and communication skills.
- Mandatory certifications: OSCP, OSWE, OSEP or CRTE.
- Good communication in French and English.