- Company Name
- Cosmote Global Solutions
- Job Title
- Expert in Secure Development
- Job Description
-
Job Title: Expert in Secure Development
Role Summary: Conduct in‑depth white‑box penetration testing on the AFIS application, identify and document security weaknesses, provide remediation guidance, and maintain traceability via ticketing systems.
Expectations: Deliver comprehensive security assessment reports, achieve thorough coverage of OWASP testing categories, support remediation activities, and facilitate knowledge transfer to the AFIS team.
Key Responsibilities:
- Perform white‑box penetration tests on the AFIS application, leveraging full source code and privileged accounts.
- Design and execute authenticated attack scenarios across predefined user roles, targeting privilege escalation and misuse of functionalities.
- Apply PTES or equivalent methodology and OWASP Testing Checklist to ensure repeatable, complete testing.
- Analyze vulnerabilities and exploitation paths; assess impact, likelihood, and relevance to AFIS security posture.
- Document findings in a detailed PDF report, including technical description, risk severity, affected components, and remediation recommendations.
- Register all defects in AFIS Ticketing (GitLab/Jira) with correct templates and severity classification.
- Advise AFIS team on remediation, mitigation strategies, and secure alternatives for high‑risk issues.
- Participate in review/clarification meetings with stakeholders to walk through findings and remediation plans.
Required Skills:
- 8+ years of offensive security testing on Web applications and infrastructure (Java, Linux, Oracle/Postgres).
- Deep knowledge of PTES, OWASP Testing Guide, NIST SP 800‑115, NIST SP 800‑115, ISSAF.
- Expert understanding of OWASP Top 10, OWASP ASVS, CWE, common vulnerability classes.
- Proficiency with modern application architectures (web, API, client‑server, microservices), secure dev practices, and coding pitfalls.
- Strong grasp of authentication/authorization models, RBAC, session management, token‑based auth.
- Expertise in network protocols, TLS, encryption, certificates, secure comm patterns.
- Ability to perform code‑assisted analysis, configuration review, dynamic and static analysis, and manual testing.
- Advanced skills in exploit development, payload crafting, evasion techniques (white‑box context).
- Proficiency with penetration testing tools: Burp Suite Pro, OWASP ZAP, Postman, Browser DevTools, source‑code review tools.
- Experience tracking defects in GitLab/Jira; knowledge of AFIS architecture (Java, Spring Boot, React, Python).
- Ability to create realistic attack chains and understand business logic security.
- Language skills: French (C2) required; Dutch (B1) advantage.
Required Education & Certifications:
- Master’s Degree in IT or related field.
- Offensive Security Certified Professional (OSCP).