Iranian company dealing only with Iranian entities
1391
Privately held
Company score
3.6
online services
ASA has been founded in 2012 by three partners, an “A” grade financial market broker (“Agah” brokerage firm) and two other IT based firms with strong background in banking and tourism technology.
The founders put all their financial and technical efforts for ASA to become a full service Fin-Tech company with more than 45 staff members developing a wide variation of solutions for financial markets.
ASA, as a fully licensed firm (by TSE), provides a wide range of integrated stock market services to Agah Clients. We started by providing an automated data delivery and analysis framework which makes clients trades more efficient. Eventually the solution will turn into a trade signal generator facilitating portfolio or wealth management processes.
On the trade side, ASA provides an agile, safe and reliable trading multi-platform (Web, IOS and android) which carries out client’s orders as well as post trade services.
We believe that an integrated social network community will improve the exchange of information between clients. Building on that, our “CRM” and “Bashghah” (customer club) services allows the broker and clients to communicate more efficiently resulting in a better understanding of their true demands.
Review and approve Security Audit Governance Checklists, assessment methodologies, audit scopes, and evaluation criteria.
Conduct and supervise security assessments and audits of applications and systems, with a particular focus on mobile applications (Android / iOS).
Perform architectural analysis and security reviews to identify potential security weaknesses, risks, and compliance gaps.
Plan, coordinate, and oversee penetration testing activities to evaluate the security of systems and applications.
Review penetration testing and security assessment results and ensure that findings are properly documented, risk-rated, and communicated to relevant stakeholders.
Prepare, review, and approve security audit and penetration testing reports, ensuring that findings, risks, evidence, and recommendations are clearly documented.
Work closely with development, infrastructure, security, and other relevant teams to understand security requirements and ensure identified risks are properly addressed.
Provide guidance and recommendations to development teams regarding remediation of identified vulnerabilities and improvement of their security posture.
Track remediation activities and audit findings through to closure, ensuring that corrective actions are assigned, followed up, and completed within agreed timelines.
Take ownership of audit findings and ensure that unresolved risks are appropriately escalated to the relevant stakeholders and management.
Monitor the status of security risks, remediation plans, and audit actions, and provide regular progress reports to management.
Establish and maintain effective security audit governance processes, including checklists, review procedures, approval workflows, evidence requirements, and reporting standards.
Ensure consistency and quality of audit activities and deliverables across the team.
Coordinate with relevant stakeholders to obtain required evidence, clarify findings, resolve disputes, and ensure timely completion of audit activities.
Identify recurring security weaknesses and provide recommendations for improving security controls, processes, and development practices.
Support continuous improvement of the organization’s security audit and assessment processes.
Technical Responsibilities
Architectural analysis and design of mobile applications in order to identify security weaknesses and possible risks
Do penetration tests (pen test) to evaluate the security of systems with a focus on mobile systems (Android / IOS)
Record full reports of penetration test results to provide detailed information about identified vulnerabilities
Work closely with development teams and other stakeholders to understand security needs
Provide guidance and suggestions to the development teams about fixing the identified vulnerabilities and their improvement
Requirements
Proven experience in Security Auditing, Security Assessment, Vulnerability Management, or Penetration Testing.
Experience leading or coordinating a security audit or security assessment team.
Strong understanding of Security Governance, Risk Management, Audit Processes, and Security Controls.
Ability to develop, review, maintain, and approve security audit governance checklists and assessment criteria.
Strong understanding of application and mobile security concepts and common attack techniques.
Familiarity with OWASP Top 10 (Web/Mobile) and other relevant security standards and frameworks.
Practical knowledge of mobile security testing and penetration testing methodologies.
Familiarity with tools such as Burp Suite, OWASP ZAP, MobSF, MitMProxy, and similar tools.
Familiarity with mobile programming languages and frameworks such as Java/Kotlin, Swift/Objective-C, React Native, and Xamarin.
Strong analytical and problem-solving skills with the ability to assess security risks and determine their potential business impact.
Strong reporting, documentation, and communication skills.
Ability to communicate effectively with development, infrastructure, security, and management teams.
Strong sense of ownership, responsibility, and accountability for assigned audits, findings, and deliverables.
Strong follow-up and task management skills, with the ability to continuously track open findings and remediation activities until closure.
Ability to prioritize multiple audits, assessments, and remediation activities while maintaining quality and meeting deadlines.
Ability to challenge findings constructively, resolve disagreements with stakeholders, and ensure that security requirements are properly addressed.
Ability to work independently while effectively leading and coordinating team members and stakeholders.