اسنپ مارکت
اسنپ مارکت

VAPT Lead

Tehran/Zaferanieh
Full Time
Saturday-Wednesday
-
Loan -Health insurance -Flexible working hours -Learning stipends -Game room -Resting space -Breakfast -Occasional packages and gifts

این فرصت شغلی چقدر برای من مناسب است؟

501 - 1000 employees
Internet Provider / E-commerce / Online Services
Iranian company dealing only with Iranian entities
2018
snappmarket
Privately held
توضیحات بیشتر

key Requirements

6 years experience in similar position
Managerial work experience
Python - Intermediate
Go - Intermediate

Job Description

Role Overview
We are looking for a hands-on Vulnerability Assessment & Penetration Testing (VAPT) Lead to lead security assessments and targeted Red Team exercises across applications, networks, infrastructure, and cloud environments. The role combines technical testing, team leadership, and collaboration with engineering and security teams to identify weaknesses, validate security controls, drive remediation, and strengthen security throughout the software development lifecycle.

Key Responsibilities
Lead and execute VAPT engagements across web and mobile applications, APIs, networks, infrastructure, cloud, Kubernetes, and container environments.
Define assessment scope and standards, including testing methodologies, rules of engagement, vulnerability severity criteria, reporting processes, and quality reviews.
Perform hands-on security testing, source code reviews, and vulnerability validation; assess business impact and prioritize security risks.
Lead Red Team and adversary-simulation exercises to identify realistic attack paths and validate security controls within authorized, clearly defined scopes. Collaborate with SOC and Blue Team to assess and improve detection and response capabilities.
Drive remediation through actionable reports, practical guidance, coordination with engineering teams, and retesting to verify fixes.
Integrate and automate security testing within the SDLC and CI/CD pipelines in collaboration with Development, DevOps, and SRE teams.
Lead and mentor VAPT engineers, review findings from internal and external sources, track security and remediation KPIs, and support incident investigations when required.

Required Skills
Penetration Testing: Strong practical experience in application, API, mobile, network, infrastructure, and cloud security assessments.
Red Team & Adversary Simulation: Hands-on experience with MITRE ATT&CK-aligned techniques, including initial access, privilege escalation, lateral movement, and defense evasion, with a strong understanding of engagement scoping and rules of engagement.
Security Assessment Techniques: Knowledge of OWASP, vulnerability exploitation, attack-path analysis, source code review, threat modeling, and security architecture.
Platform Security: Understanding of Linux, Windows, Kubernetes, containers, authentication, authorization, databases, and middleware security.
Tools & Automation: Proficiency with Burp Suite, Nmap, Metasploit, and scripting in Python, Bash, or Go.
DevSecOps: Experience with CI/CD security testing, including SAST, DAST, SCA, secret scanning, container scanning, and Infrastructure as Code (IaC) scanning.
Technical Leadership: Ability to mentor engineers, ensure assessment quality, communicate security risks clearly, and drive remediation across teams.

Job Requirements

Gender
Men / Women
Software
Python| Intermediate Go| Intermediate

ثبت مشکل و تخلف آگهی

ارسال رزومه برای اسنپ مارکت