Senior Security Engineer

Start a journey of growth and discovery at Ebryx, where your ideas matter and your career can flourish. Join a team that values your creativity and contributions, providing a dynamic environment to innovate, learn, and excel.

We are looking for an experienced Senior Security Engineer to become part of our growing team. The ideal candidate will be dedicated to safeguarding digital assets, with a strong focus on security best practices. You should be highly collaborative and committed to delivering high-caliber protection, always keeping the needs of our clients at the forefront.

Apply Now

Senior Security Engineer

Responsibilities:

As a Senior Security Engineer specializing in Offensive Security, you'll be responsible for performing pentest activities across various domains, including: Conducting in-depth penetration testing for Web & APIs, Mobile Applications, Cloud environments (AWS), and Active Directory.

Required Expertise:

Web Application and API Pentest:

  • Demonstrated expert-level knowledge of web application functioning, authentication, and authorization mechanisms.
  • Proficiency in identifying and understanding code-level vulnerabilities, including OWASP Top 10, and collaborating with development teams for effective remediation.

Mobile Applications:

  • Comprehensive understanding of platform-native vulnerabilities and strategies for remediation.
  • Understanding in SSL Pinning and root check implementation, including circumvention these security measures and improvement suggestions.

Cloud - AWS:

  • Strong familiarity with major AWS services (IAM, EC2, Lambda, S3, RDS, etc.).
  • Ability to identify misconfigurations in IAM policies and hands-on experience in initial access, enumeration, privilege escalation, and data exfiltration in cloud environments.
  • Articulate knowledge of prevention and remediation strategies for identified cloud Vulnerabilities.

Good to Haves:

  • Certifications such as OSCP, CRTP, CRTO, CREST CRT are advantageous but not mandatory; emphasis is on practical skills and expertise.
  • Hands-on experience in performing the Active Directory Assessment and familiarity with CI/CD Pipelines.

Experience:

3 Years plus

Location:

Lahore/Karachi/Islamabad

Apply Now

Apply Now