17 views
WhiteBIT
WhiteBIT is a global fintech company with a team of over 1,100 professionals. As a cryptocurrency exchange serving more than 5 million users worldwide, we are committed to delivering top-tier services through an intuitive interface and a robust set of analytical tools. By partnering with cryptocurrency projects globally, our mission is to promote the widespread adoption of blockchain technology, guided by the principles of security, expertise, and innovation.
We are looking for a Penetration Tester!
Requirements:
- 1-3 years of experience in penetration testing.
- Solid understanding of the SDLC and testing methodologies.
- Knowledge of OWASP Top Ten (Web, Mobile, API).
- Proficiency with penetration testing tools and frameworks (e.g., Burp Suite, Metasploit, etc.).
- Strong understanding of secure coding practices and vulnerability management.
- Familiarity with security concepts like authentication, authorization, session management, and API protection.
- Knowledge of iOS/Android security, including static and dynamic analysis.
- Hands-on experience with Linux/Unix systems.
- Skilled in creating technical documentation.
- Upper- Intermediate level of English (written and spoken) to communicate findings and collaborate with global teams effectively.
- Strong analytical and problem-solving skills.
Responsibilities:
- Conduct penetration tests of web and mobile applications (including APIs) to uncover vulnerabilities and assess security risks.
- Smart contract auditing.
- Prepare comprehensive and detailed reports with findings, risk assessments, and actionable recommendations.
- Collaborate with development teams to implement secure coding practices across the SDLC (Software Development Life Cycle).
- Develop realistic attack scenarios to simulate potential cyber threats.
- Contribute to internal security training programs, fostering awareness and improving team skills.
Would be a plus:
- Basic coding or scripting knowledge (e.g., Python, Bash).
- Experience with Docker, Kubernetes, and CI/CD tools.
- Familiarity with WAF testing.
- Understanding of security standards such as ISO 27001, PCI-DSS, and GDPR.
- Relevant certifications: CISSP, CEH, CISM, CompTIA Security+, or others.
Job conditions:
– Our own product
– Annual paid vacations
– Sick leave compensation
– Professional working environment
We provide challenging tasks that offer continuous growth opportunities for everyone. We've consistently embraced development and the advancement of our colleagues, ensuring work is always engaging. Our team is prepared to offer support, share expertise, and lend a helping hand when needed.