Senior Penetration Testing Analyst
ประกาศจากแหล่งภายนอกคุณสมัครได้โดยตรง — เราจะพาคุณไปยังหน้าสมัครงานของบริษัท ไม่ต้องสมัครสมาชิก ไม่มีคนกลาง ไม่ต้องล็อกอิน ThaiJobz
รายละเอียดงาน
About the Company
Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.
About the Role
シニアペネトレーションテストアナリストは、情報セキュリティ脅威インテリジェンスを適用し、クライアント環境内の脆弱性を特定・悪用することでサポートを行います。本役職の重点分野は、アプリケーションセキュリティ(Webアプリケーションペネトレーションテスト、APIテスト)、またはネットワークセキュリティ(脆弱性評価、外部ペネトレーションテスト、内部ペネトレーションテスト等)、レッドチームテスト(サイバー攻撃シミュレーション)のいずれかです。両方の経験は必須ではありませんが、あれば尚可です。
The Senior Penetration Testing Analyst supports by applying information security threat intelligence to identify and exploit vulnerabilities within our client’s environments. The focus area for this role is either application security (web application penetration testing, API testing), network security (vulnerability assessments, external penetration tests, internal penetration tests, etc.), or Red Team Testing (cyberattack simulation). Candidates are not expected to be experienced in all areas although that would be a plus.
Responsibilities
- Conduct application security assessments (web, mobile, API, etc.) using off-the-shelf or internally developed exploitation tools to execute manual testing for advanced attacks OR conduct network penetration testing assessments (external pen test, internal pen test, etc.).
- Produce and deliver vulnerability and exploit information to clients in the form of a professional security assessment report, including evidence, reproduction steps and remediation recommendations.
- Conduct client conference calls including project kick-off calls, notification of high/critical findings during testing, and close-out calls to review test findings and remediation.
- Perform proactive research to identify and understand new threats, vulnerabilities, and exploits.
- Conduct exploitation testing using commercial or self-developed tools and document findings for client remediation.
- Excel as both a self-directed individual contributor and as a member of a larger team; technically help and influence junior teammates to grow together.
- Lead our security services as a service owner and perform other essential duties as assigned.
Qualifications
- ペネトレーションテストにおける最低 2 年の経験
- Nmap、Metasploit、Kali Linux、Burp Suiteのうち、少なくとも1つを2年以上使用した経験があること
- ネイティブレベルの日本語能力(最低限、ビジネスレベルの日本語能力が必要)
- Minimum of 5 years of experience with web application or penetration testing
- Minimum of 5 years of experience with at least one of the following: Nmap, Metasploit, Kali Linux, Burp Suite
Desirable
- Offensive certifications such as GPEN, GWAPT, OSCP, OSEP, OSWE, OSWP etc.
- Understanding of TCP/IP networking at a technical level
- Bachelor of Science degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical field; or equivalent professional experience
- Experience with various application attack vectors, security test processes and strong knowledge of common vulnerabilities (i.e. OWASP Top 10)
- Experience with penetration testing skills against Windows Active Directory or various cloud services such as AWS/Azure/GCP
- Working knowledge of SQL and high-level languages
- Business-level English language skills
- Good technical communication skills, both written and verbal; good analytical and problem-solving skills
- Ability and relevant experience in influencing teammates technically, to help them to succeed in their assigned projects.
Benefits
Sophos operates a remote-first working model, making remote work the primary option for most employees.
Additional Information
At Sophos, we believe in the power of diverse perspectives to fuel innovation. Research shows that candidates sometimes hesitate to apply if they don't check every box in a job description. We challenge that notion. Your unique experiences and skills might be exactly what we need to enhance our team. Don't let a checklist hold you back – we encourage you to apply.
คุณสมบัติผู้สมัคร
- ประสบการณ์
- 6-10 ปี
- การศึกษา
- ไม่ระบุ
