Job description
Company culture :
Aba Technology is a company driven by innovation, where creativity, experimentation, and bold thinking shape everyday work. This entrepreneurial mindset is supported by strong structure and process discipline, ensuring efficiency and consistent quality. Teams thrive in a collaborative and caring environment that values trust, support, and close teamwork. While performance and competition play a lighter role, the focus remains on agility, collective alignment, and impactful innovation.
Job :
Penetration Testing (Pentest):
• Plan and conduct application penetration tests (web, REST/GraphQL API, mobile) in black, gray, and white box.
• Perform configuration audits and targeted security code reviews.
• Exploit vulnerabilities in a controlled manner to demonstrate their real impact (proof of concept).
• Cover OWASP Top 10, OWASP ASVS, OWASP API Security Top 10, and OWASP Testing Guide repositories.
• Write clear and prioritized audit reports (management summary + technical detail), with remediation recommendations.
• Perform re-audits to verify vulnerability remediation.
• Participate in bug bounty programs and manage external reports if applicable.
Compliance and Governance:
• Manage and maintain compliance with repositories: ISO 27001/27002, GDPR (and Moroccan Law 09-08 on personal data protection).
• Conduct risk analyses (EBIOS RM, ISO 27005) on projects and applications.
• Write and maintain security policies, standards, and procedures (PSSI, charters, secure development standards).
• Prepare and support internal and external certification audits.
• Monitor action and remediation plans with the relevant teams.
• Integrate security into projects from the design phase (Security by Design, architecture reviews).
Awareness and Continuous Improvement:
• Train and raise developers' awareness of application security (secure coding, workshops, internal CTFs).
• Maintain active monitoring of vulnerabilities (CVEs, exploits, advisories) and regulatory changes.
• Contribute to the response to security incidents (analysis, containment, lessons learned).
Required profile :
Hard Skills:
• Education: Master's degree (Bac+5) in cybersecurity, computer science, or equivalent.
• Experience: Minimum 3 years in penetration testing and/or security auditing, with exposure to compliance topics.
• Valued Certifications: OSCP, eWPT/eWPTX, BSCP (Burp Suite Certified Practitioner), CEH, ISO 27001 Lead Implementer/Auditor, CISA.
• Web/API Pentest: Proficiency in Burp Suite Pro, OWASP ZAP, Nmap, Nuclei, sqlmap, Metasploit, ffuf/dirsearch.
• Application Vulnerabilities: Injections (SQLi, XSS, SSTI, SSRF), IDOR/BOLA, authentication and session flaws, deserialization, CSRF, misconfigurations.
• Development: Code reading (JavaScript/Node.js, Python), exploitation scripting (Python, Bash).
• Protocols and Web: HTTP/S, TLS, OAuth2/OIDC, JWT, SAML, WebSockets.
• Compliance: ISO 27001, GDPR/Law 09-08, PCI-DSS; EBIOS RM / ISO 27005 methodologies.
• GRC Tools: Proficiency in a risk/compliance management tool is a plus.
Soft Skills:
• Impeccable ethics and strict adherence to the legal framework of tests.
• Curiosity and offensive creativity ("attacker mindset").
• Excellent writing skills (reports for technical and non-technical audiences).
• Pedagogical approach, diplomacy, and ability to engage with business units and management.
وصف الوظيفة
ثقافة الشركة :
Aba Technology هي شركة تقودها الابتكار، حيث تشكل الإبداع والتجربة والتفكير الجريء العمل اليومي. يدعم هذا mindset ريادة الأعمال وجود هيكل وصرامة عمليات قوية، لضمان الكفاءة والجودة المتسقة. تنمو الفرق في بيئة تعاونية ومهتمة تقدر الثقة والدعم والعمل عن قرب ضمن فريق. بينما تلعب الأداء والمنافسة دوراً أقل، يظل التركيز على الرشاقة والتوافق الجماعي والابتكار ذو الأثر.
الوظيفة :
اختبار الاختراق (Pentest):
• تخطيط وإجراء اختبارات اختراق التطبيقات (ويب، REST/GraphQL API، موبايل) بنطاقات الأسود والرمادي والأبيض.
• إجراء تدقيقات التكوين ومراجعات أمان الشيفرة المستهدفة.
• استغلال الثغرات بشكل محكم لإظهار أثرها الحقيقي (إثبات المفهوم).
• تغطية مستودعات OWASP Top 10، OWASP ASVS، OWASP API Security Top 10، وOWASP Testing Guide.
• كتابة تقارير تدقيق واضحة ومفصلة مع توصيات الإصلاح (ملخص إداري + تفاصيل تقنية).
• إجراء إعادة تدقيق للتحقق من إصلاح الثغرات.
• المشاركة في برامج مكافأة الثغرات وإدارة التقارير الخارجية إذا كان ذلك قابلاً للتطبيق.
الامتثال والحوكمة:
• إدارة والالتزام بالمستودعات: ISO 27001/27002، GDPR (وقانون المغرب 09-08 لحماية البيانات الشخصية).
• إجراء تحليلات مخاطر (EBIOS RM، ISO 27005) للمشروعات والتطبيقات.
• كتابة والحفاظ على السياسات الأمنية والمعايير والإجراءات (PSSI، ميثاق، معايير التطوير الآمن).
• إعداد ودعم عمليات التدقيق والشهادات الداخلية والخارجية.
• متابعة خطط العمل والإصلاح مع الفرق المعنية.
• دمج الأمن في المشاريع من مرحلة التصميم (الأمن بالتصميم، مراجعات المعمارية).
الوعي والتحسين المستمر:
• تدريب وزيادة وعي المطورين بأمان التطبيقات (برمجة آمنة، ورش عمل، مسابقات CTF داخلية).
• متابعة نشطة للثغرات (CVEs، الاستغلالات، النشرات) والتغييرات التنظيمية.
• المساهمة في الاستجابة للحوادث الأمنية (التحليل، الاحتواء، الدروس المستفادة).
الملف الشخصي المطلوب :
المهارات التقنية:
• التعليم: درجة الماجستير ( Bach+5) في الأمن السيبراني، علوم الحاسب، أو ما يعادلها.
• الخبرة: الحد الأدنى 3 سنوات في اختبار الاختراق و/أو تدقيق الأمان، مع تعرض topic الامتثال.
• الشهادات المُقدَّرة: OSCP، eWPT/eWPTX، BSCP (Burp Suite Certified Practitioner)، CEH، ISO 27001 Lead Implementer/Auditor، CISA.
• pentest الويب/API: الكفاءة في Burp Suite Pro، OWASP ZAP، Nmap، Nuclei، sqlmap، Metasploit، ffuf/dirsearch.
• ثغرات التطبيقات: الحقن (SQLi، XSS، SSTI، SSRF)، IDOR/BOLA، عيوب المصادقة والجلسة، فك التسلسل، CSRF، سوء الإعدادات.
• التطوير: قراءة الشيفرة (JavaScript/Node.js، Python)، برمجة الاستغلال (Python، Bash).
• البروتوكولات والويب: HTTP/S، TLS، OAuth2/OIDC، JWT، SAML، WebSockets.
• الامتثال: ISO 27001، GDPR/Law 09-08، PCI-DSS؛ منهجيات EBIOS RM / ISO 27005.
• أدوات GRC: الكفاءة في أداة إدارة المخاطر/الامتثال تعتبر إضافة مفيدة.
المهارات الشخصية:
• أخلاقيات لا تشوبها شائبة والالتزام الصارم بالإطار القانوني للاختبارات.
• فضول وإبداع هجومي (عقلية المهاجم).
• مهارات كتابة ممتازة (تقارير لجمهور تقني وغير تقني).
• منهج تربوي، دبلوماسية، والقدرة على التواصل مع وحدات الأعمال والإدارة.