In ShahrzadCity, we are looking for a Senior Offensive Security Engineer to join the Network Security Team. Key Responsibilities
Conduct comprehensive penetration testing (black-box, grey-box, and white-box) across web applications, APIs, microservices, and internal services.
Identify and report high-impact vulnerabilities, including: - Authentication and authorization bypass - Access control issues (e.g., IDOR) - SSRF, injection flaws, session/JWT weaknesses - Business logic vulnerabilities - Sensitive data exposure and security misconfigurations
Deliver security assessments within agreed timelines and provide clear, reproducible, risk-based reports with evidence and remediation guidance.
Triage, validate, and prioritize vulnerabilities discovered through testing or reported by internal/external sources; determine severity based on exploitability and business impact.
Validate remediation actions and ensure Critical/High issues are fully resolved prior to production release.
Create threat models for new applications/features to identify attack paths and prioritize security controls.
Support DevSecOps by reviewing and helping tune findings from: SAST/DAST, secret scanning, dependency scanning, and container security.
Integrate and optimize SAST/DAST and related security checks into CI/CD pipelines.
Required Qualifications
5+ years of professional experience in penetration testing, application security, or offensive security.
Advanced knowledge of web application and API security.
Strong understanding of OWASP Top 10.
Strong experience with tools such as Burp Suite (preferably Pro), Nmap, Nuclei, OWASP ZAP, Wireshark, and Kali Linux.
Solid understanding of Linux, Docker, Kubernetes, and CI/CD environments and pipelines.
Hands-on experience implementing and tuning AppSec/DevSecOps tools such as Semgrep, Gitleaks, Trivy, DefectDojo, and dependency scanning tools.
Ability to build security automation/scripts using Bash, Go, Python, PHP, or similar.
Strong analytical and problem-solving skills with high attention to detail.
Strong technical documentation and reporting skills; ability to communicate effectively with both technical and non-technical stakeholders.
Ability to work independently, manage multiple concurrent assessments, and take ownership of security risk.