Security Penetration Tester (México)

Security Penetration Tester (México)

23 ago
|
Deloitte
|
México

23 ago

Deloitte

México

Application Security Penetration Tester - Senior Consultant – Americas Delivery Mexico (ADMX)

Are you an experienced, passionate pioneer in technology? A Security Penetration Tester - Senior Consultant who wants to work in a collaborative environment? As an experienced Security Penetration Tester you will have the ability to share new ideas and collaborate on projects as a consultant without the extensive demands of travel. Americas Delivery Mexico (ADMX) leverages scale and talent to provide high quality, cost-effective service to our clients.

ADMX is a member of the Integral Delivery Network which has presence across the world with Delivery centers in the United States, Romania, India, Spain, China, and the Philippines. ADMX is in Queretaro, Mexico. We provide consulting services to help our clients achieve a higher level of service in operational efficiency and business value.

We are a team of professionals passionate about serving clients with distinction and learning, and we are driven by our purpose: Making an impact that matters for our clients, our people, and society.

Work you’ll do/Responsibilities

As a Senior Consultant, you will work with diverse global clients across a wide range of industries. You will have a variety of client facing responsibilities such as diagnosing issues using advanced analytical techniques, interviewing staff, formulating and making recommendations, and helping clients implement proposed solutions

- Conduct vulnerability assessments and manual penetration testing for Web, API, Thick Client and mobile applications.
- Perform secure code review and false positive analysis for vulnerabilities reported by industry standard tools such as SAST and DAST scanners.
- Respond to requests for ad-hoc vulnerability reporting and research topics from management and analysts as required.
- Identify and prioritizes security vulnerabilities.
- Coordinate with the application development teams and operations teams to assist and advise on remediations plans and securing applications.

The Team

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Qualifications

Required

- 6-10+ years of consulting and/or industry experience.




- Completion of course of study/Egresado in Computer Science/IT/Computer Engineering, or any pertinent field or industry, or equivalent years of experience.
- Responsible for supporting and leading project workstreams and/or teams.
- Identifies key drivers, defines problems, and proposes solutions.
- Advanced English level.
- hands-on experience in application security, vulnerability assessment, penetration testing, mobile application security, thick client and web API security assessments.
- Strong understanding of OWASP Top 10 vulnerabilities but not limited to manual assessment and exploitation of vulnerabilities such as Blind SQLi, XXE, SSRF, Insecure Deserialization, HTTP Request Smuggling etc.
- Strong understanding of OAUTHv2/OpenID standards and associated vulnerabilities.
- Strong understanding of business logic vulnerabilities.
- Experience in Secure Code Review in-line with OWASP Secure Coding Practices.
- Proficiency in industry standard tools such as Burp Suite, Fiddler, Sysinternals suite, Veracode, DnSpy, Olly debugger, IDA Pro, EchoMirage, Wireshark, Apktool, Jadx-gui, Frida etc.
- Ability to perform manual penetration testing and security assessments as well using automated tools.
- Excellent technical report writing skills.
- Understanding in web development technologies including HTML, CSS, JavaScript, PHP, JAVA, .Net and backend databases.
- Experience with reviewing application security architectures and threat modelling.
- Understand on the basic concepts of reverse engineering, memory analysis etc.
- Understanding of basic networking protocols such as TCP/IP, DNS, HTTP/s
- Understanding of vulnerability classification using National Vulnerability Database nomenclature such as CVE/CVSS
- A relevant cybersecurity certification, which may include Certified Information Systems Security Professional (CISSP), Offensive Security Certified Professionals (OSCP), Offensive Security Web Expert (OSWE), Burp Suite Certified Practitioner (BSCP), Web Application Penetration Tester (GWAPT) or similar.

Applicants must be legally authorized to work in Mexico at the time of hire; limited sponsorship may be available for this role based on business needs and applicable law.

Preferred





- Experience testing AI based applications and systems is preferred.
- Relevant publications such as blogs, tools, conference presentations and CVEs are preferred.
- Offensive Security Web Expert (OSWE) and Burp Suite Certified Practitioner (BSCP) certifications are preferred.
- Experience with automation and scripting (Python) are preferred.
- Outstanding English written and oral communication skills and the ability to prioritize work.
- Strong understanding of web, mobile and microservices vulnerabilities.
- Working knowledge of how malicious code operates and how technical vulnerabilities are exploited.
- Strong analytical and problem-solving skills.
- Self-motivated to upskill and learn new attack vectors.
- A strong desire to understand the what as well as the why and the how of security vulnerabilities.

Benefits

At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits

Learn more about what working at Deloitte can mean for you.

Our people and culture

Our inclusive culture empowers our people to be who they are, contribute to their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ideas and perspectives and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work.

Professional development

From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect, and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.

Accommodations

We are committed to providing equal opportunity and reasonable accommodation for people with disabilities. To request a reasonable accommodation, contact our Talent Relations team at [email protected]

As used in this posting, "Deloitte" means Deloitte Consulting LLP, a subsidiary of Deloitte LLP. Please see www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte LLP and its subsidiaries.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

📌 Security Penetration Tester (México)
🏢 Deloitte
📍 México

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: security penetration tester (méxico) / méxico

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: security penetration tester (méxico) / méxico