TP-Link Systems Inc. logo
TP-Link Systems Inc.
Verified live 15h ago

Penetration Tester, Web/Mobile Apps and Cloud Services

Brief overview

Irvine, CAIn-person
UndergradOr in progress
$80k–$132k/yrStated range
1+ yrsMinimum
Web application securityCloud security conceptsAPI securityOWASP Top 10Penetration testing tool optimizationAutomation strategies for cloud environmentsSAST results analysisFalse positive identificationProgramming (Python, JavaScript, Bash, PowerShell)Cloud platforms (AWS, Azure, GCP)Security controlsThreat modelingIncident responseVulnerability managementCloud security configuration analysisSecurity tool developmentCI/CD security integration

Job description

Summary

TP-Link Systems Inc. is a global provider of reliable networking devices and smart home products. They are seeking a skilled and proactive Penetration Tester to support cloud service projects, focusing on penetration testing, threat modeling, and security assessments to enhance the security of their cloud services.

Responsibilities

  • Penetration Testing: Perform penetration testing on cloud services, web applications, and APIs to identify vulnerabilities. Provide remediation recommendations and write detailed penetration test reports
  • Threat Modelling and security assessment: Perform threat modeling to identify and evaluate potential risks for specific cloud components and web applications
  • Incident Response and Vulnerability Management: Support cloud and web application incident response, including investigation, containment, remediation, and post-incident analysis. Coordinate with cross-functional teams to ensure effective resolution
  • Cloud security configuration: Analyze cloud security configurations and identify misconfigurations that could lead to vulnerabilities
  • Develop security tools: Assist in developing various pen-testing tools, automated testing platforms, and scripts to enhance testing efficiency and accuracy for cloud environments
  • CI/CD Security Integration: Participate in the development and improvement of the company's CI/CD security processes, ensuring security considerations are integrated throughout the development lifecycle
  • Interpret cloud security standards and regulatory requirements, supporting implementation of security requirements

Skills

  • Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent work experience)
  • Proven 1-3 years experience as a Security Engineer (Cloud & Web) or in a similar role
  • Strong knowledge of web application security, cloud security concepts, API security, and common vulnerabilities (OWASP Top 10)
  • Experience with security tools such as Burp Suite, OWASP ZAP, Nmap, Kali, Nessus, Metasploit, etc
  • Capability to optimize penetration testing tools and automation strategies for cloud environments
  • Ability to analyze SAST results and identify false positives
  • Proficient in at least one programming language (e.g., Python, JavaScript, Bash, or PowerShell)
  • Familiarity with major cloud platforms (AWS, Azure, GCP) and their security controls
  • Relevant security certifications (e.g., CEH, OSWP, etc.) are highly preferred
  • Published CVEs are highly preferred

Qualifications

Must Haves

  • Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent work experience)
  • Proven 1-3 years experience as a Security Engineer (Cloud & Web) or in a similar role
  • Strong knowledge of web application security, cloud security concepts, API security, and common vulnerabilities (OWASP Top 10)
  • Experience with security tools such as Burp Suite, OWASP ZAP, Nmap, Kali, Nessus, Metasploit, etc
  • Capability to optimize penetration testing tools and automation strategies for cloud environments
  • Ability to analyze SAST results and identify false positives
  • Proficient in at least one programming language (e.g., Python, JavaScript, Bash, or PowerShell)
  • Familiarity with major cloud platforms (AWS, Azure, GCP) and their security controls

Nice to Haves

  • Relevant security certifications (e.g., CEH, OSWP, etc.) are highly preferred
  • Published CVEs are highly preferred

Benefits

  • Fully paid medical, dental, and vision insurance (partial premium coverage for dependents)
  • Employer quarterly contributions to 401k funds
  • 15 days accrued vacation
  • 11 paid holidays
  • Bi-annual reviews, and annual pay increases
  • Health and wellness benefits, including free gym membership
  • Quarterly team-building event

More jobs like this