The #1 platform that brings everything marketing and customer engagement teams need in one place, to become unstoppable.
Senior Security Engineer – Red Team
Location
Turkey
Posted
76 days ago
Salary
0
Seniority
Senior
Job Description
Senior Security Engineer – Red Team
Insider One
• performs web, mobile application, and internal penetration tests, source code reviews, threat analysis, social-engineering assessments, • supports blue teams when needed, • researches new attack vectors and stays current with cybersecurity news and trends, • trains Quality Assurance and Development teams in standard security testing techniques and secure software development.
Job Requirements
- have 4+ years of working experience in web application security,
- have hands-on experience in security testing of web applications, web services, mobile applications, APIs, etc.,
- have experience securing REST APIs and web services,
- have experience using and implementing SAST / DAST tools such as Fortify, Veracode, Checkmarx, or other similar tools,
- know how to conduct penetration tests of information systems using commercial and open-source exploitation tools,
- have a good understanding of standard security vulnerabilities and common remediation as published by OWASP, SANS, etc.,
- have experience working with secure coding methodology and best practices and their implementation within engineering teams,
- will support developers of our business units in their SDLC and provide guidance regarding mitigations to emerging threats,
- will review application source code based on static application security testing tools,
- will be engaging in security research to remain current on vulnerabilities and testing tools,
- will be creating detailed, professional documentation/reports that clearly communicate vulnerabilities, mitigation strategies, and remediation steps,
- have the ability to work on multiple projects concurrently and be committed to providing exemplary customer service,
- have strong written and verbal communication skills in English,
- have Python, JavaScript, PHP programming experience as a plus,
- have knowledge in scripting (any language) and experience in automation scripts for application security testing as a plus,
- have familiarity with cloud security, particularly AWS security concepts, as a plus,
- have certifications such as eWAPTx, OSCP, OSWE, etc., as a plus,
- are able to work in a team-centric environment,
- have strong critical thinking and analytical skills,
- have experience in executing white, gray, or black box security posture assessments and completing detailed reports that outline the findings and recommendations.
Benefits
- Enjoy a monthly meal allowance designed to enhance your daily routine.
- Access comprehensive private health insurance.
- Feed your curiosity with access to Spotify, LinkedIn Learning, Blinkist, MasterClass, Neoskola, and CloudGuru.
- Level up with internal trainings covering AI fundamentals, coding, foreign languages, and a wide range of personal development skills.
- Be part of a diverse team that’s as global as it gets, where every voice is heard and 50+ nationalities build together.
- Become a Shareowner through our eligibility-based “ESOP” and own a piece of what you build.
- Help build the team you want to work with and enjoy rewarding referral bonuses.
- Opportunities to give back to your community through volunteering and purpose-driven social impact projects.
- From global retreats to team-building activities, expect year-round events that turn into lifelong memories.
- Get inspired by the greatest minds in the tech industry through events like our Tech & Dev Talks.
- Work from anywhere in Turkey through our fully remote setup.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Drive ISO 27001 certification and SOC 2 Type II attestation initiatives end-to-end • Build and mature NetBrain’s GRC (Governance, Risk & Compliance) program • Translate compliance framework requirements into practical security policies and procedures • Define and enforce IAM (Identity & Access Management) standards • Implement and manage SIEM platforms for centralized security monitoring • Own the vulnerability management lifecycle • Develop and maintain incident response plans, playbooks, and escalation procedures • Evaluate and manage third-party vendor risk • Design and deliver security awareness training programs • Serve as the trusted security subject matter expert across business units
Senior Offensive Security Consultant – Alpha Group
VerSprite CybersecurityA counterculture cybersecurity firm emulating cybercriminal intent for the purposes of refined risk identification.
• Lead penetration testing engagements across web applications, APIs, and enterprise infrastructure • Perform advanced application security testing including business logic flaws and authentication weaknesses • Conduct internal and external network penetration testing • Lead Red Teaming engagements. • Perform threat modeling exercises (e.g., PASTA methodology) • Conduct cloud security assessments across AWS, Azure, and GCP • Perform mobile application security testing (Android and iOS) • Develop custom payloads and exploitation techniques • Produce detailed technical reports including proof-of-concept exploitation scenarios • Communicate technical findings and risk to client stakeholders • Mentor junior consultants during engagements • Contribute to internal research initiatives and security methodology improvements
Senior Security Consultant
VerSprite CybersecurityA counterculture cybersecurity firm emulating cybercriminal intent for the purposes of refined risk identification.
• Conduct web application and API penetration testing • Perform internal and external network security assessments • Assist in Active Directory security testing • Develop proof-of-concept exploits for discovered vulnerabilities • Document findings and produce clear vulnerability reports • Provide remediation recommendations • Collaborate with senior consultants during complex engagements • Continuously improve offensive security skills through research and training
Certified Ethical Hacker
VikingCloudThe leading Predict-to-Prevent cybersecurity and compliance company.
• Ethical hacking and penetration testing • Vulnerability assessment • Malware analysis • Work with other penetration testers and information security analysts • Web application security • Social engineering • Database security • Reverse engineering • Network security • Threat modeling and risk assessment


