Remote/ Taipei, Taiwan Hybrid Employment

Cymetrics is hiring a Security Engineer (Red Teaming/Penetration Testing), Cymetrics

职责

  • 規劃以及執行紅隊演練、滲透測試,協助客戶發現漏洞並進行改善且驗證修復結果。
  • 與客戶進行專案會議,開會溝通,釐清並協助客戶解決問題。
  • 協助自動化資安工具開發,與軟體工程團隊一同完成自有 SaaS 產品。
  • 與產品開發團隊合作,協助改進資安產品及平台。
  • 研究網站或開源專案漏洞,將研究結果寫成文章發佈至公司的技術文章部落格。

任职要求

  • 三年以上紅隊演練、滲透測試,善於對內部網路橫向移動與滲透。
  • 對現代 Web 框架(如React, Angular, Vue.js)和客戶端安全弱點(例如XSS, CSRF, CSP bypass, GraphQL等)理解,並熟悉其背後原理。
  • 熟悉 OWASP 測試指南和其他安全測試方法,對網頁漏洞、作業系統、網路架構有深入理解,並熟悉其背後原理。
  • 能夠清晰地整理和撰寫測試結果及修補建議,並有效地與團隊和客戶溝通。
  • 流利的中英文聽說能力,並與客戶講解滲透測試報告內容。

加分项

  • 對區塊鏈相關的資安技術有興趣
  • 有打過知名廠商 bug bounty 或是參加過國際 CTF 的經驗 (或有同等 CVE 弱點)
  • 擁有 OSWE、OSEP 或 OSCP 證照 (或其它同等資訊安全證照)
  • 擅長撰寫資安相關之技術文章(漏洞研究、CTF writeup 等等)
  • 參與過開源項目,展現對安全社群的貢獻和合作精神。

其他信息

  • 流利的中英文聽說能力,並與客戶講解滲透測試報告內容。
About company
Cymetrics
Cymetrics is one of the leading cybersecurity solution providers in Asia, offering exclusive high-end cybersecurity products. We specialize in professional red teaming, penetration testing and vulnerability scanning services, assembling a team with engineering expertise and cybersecurity specialization. Team members possess professional knowledge in cybersecurity risk management and penetration testing, with extensive experience in major consulting firms, leading cybersecurity service providers, and renowned brand OEMs. They actively participate in international CTF (Capture The Flag) competitions, achieving top three places globally. Our clientele spans diverse industries, including government, finance, manufacturing, high-tech, and e-commerce, among others. Additionally, our team assists the group in obtaining ISO 27001 and ISO 27017 certifications, reinforcing the group's cybersecurity governance. The core values of our team lie in innovation, professionalism, and collaboration, aiming to deliver efficient cybersecurity solutions. Our cybersecurity team, Cymetrics, is committed to providing a comprehensive cybersecurity assessment SaaS platform. With expertise in risk management and penetration testing, our team includes professionals from Big 4 consulting, leading cybersecurity services provider global banks, and top cybersecurity firms. Cymetrics excels in international CTF competitions, achieving a top-three global ranking and securing 1st place in the prestigious 2024 HITCON Cyber Range blue team. competition. Cymetrics supports clients across government, finance, manufacturing, high-tech, and e-commerce sectors. We’ve also secured ISO 27001 and ISO 27017 certifications for our group. Focused on innovation and collaboration, Cymetrics provides an AI security and LLM verification platform to assess AI models for vulnerabilities and Responsible AI compliance.
All jobs at Cymetrics Visit website
Job Details
Department Cymetrics
Category security
Posted 18 days ago