دیجی کالا
دیجی کالا

Security Engineer

Tehran/ Vanak
Full Time
شنبه تا چهارشنبه
-
-
More than 5001 employees
IT / Software / Hardware
Iranian company dealing only with Iranian entities
1385
Privately held
توضیحات بیشتر

key Requirements

5 years experience in similar position
Go - Intermediate
Wireshark - Intermediate
Linux - Intermediate
Docker - Intermediate
Kubernetes - Intermediate

Job Description

Overview:

The Senior Security Engineer is part of Digikala’s Offensive Security team and is responsible for identifying and reducing security risks across web applications, APIs, and supporting services. The role exists to detect vulnerabilities before they can be exploited, support secure product delivery, and help development teams remediate security issues effectively. This position works closely with Development, DevOps, Cloud, SOC, Infrastructure, and Product teams.

Responsibilities:

  • Perform comprehensive black-box, grey-box, and white-box penetration testing of web applications, APIs, microservices, and internal services. Identify high-impact vulnerabilities, including authentication bypass, authorization issues, IDOR, SSRF, injection flaws, business logic weaknesses, and sensitive data exposure.
  • Complete assigned security assessments within agreed timelines and provide clear, reproducible, and risk-based reports.
  • Validate remediation actions and ensure that critical and high-severity vulnerabilities are properly resolved before production deployment.
  • Support DevSecOps processes by reviewing findings from SAST, DAST, secret scanning, dependency scanning, and container security tools.
  • Conduct threat hunting activities for exposed assets, vulnerable services, leaked credentials, public repositories, and newly published CVEs.
  • Provide practical remediation guidance and work directly with engineering teams to reduce security risks.
  • Improve penetration-testing methodologies, automation scripts, security rules, and internal technical documentation.

Requirements:

  • At least five years of professional experience in penetration testing, application security, or offensive security.
  • Advanced knowledge of web application and API security.
  • Strong understanding of OWASP Top 10 and OWASP API Security Top 10.
  • Hands-on experience with REST APIs, GraphQL, authentication, authorization, OAuth 2.0, OpenID Connect, JWT, and session management.
  • Strong experience identifying complex business logic and access-control vulnerabilities.
  • Proficiency with tools such as Burp Suite Professional, Nmap, Nuclei, OWASP ZAP, and Wireshark.
  • Knowledge of Linux, Docker, Kubernetes, cloud environments, and CI/CD pipelines.
  • Familiarity with DevSecOps tools such as Semgrep, Gitleaks, Trivy, DefectDojo, and dependency-scanning solutions.
  • Ability to develop security automation using Bash, Go, or similar languages.
  • Strong analytical thinking, problem-solving, and attention to detail.
  • Ability to assess technical findings based on exploitability and business impact.
  • Strong technical reporting and documentation skills.
  • Effective communication and teamwork across technical and non-technical teams.
  • Ability to work independently, manage multiple assessments, and take ownership of security risks.
  • Ability to mentor junior security engineers and review penetration-testing results.
  • Certifications such as OSCP, OSWE, OSEP, BSCP, or similar are preferred but not mandatory.

Job Requirements

Gender
Men / Women
Software
Wireshark| Intermediate Linux| Intermediate Docker| Intermediate Kubernetes| Intermediate Go| Intermediate

ثبت مشکل و تخلف آگهی

ارسال رزومه برای دیجی کالا

insight applicant

مقایسه من با 25 متقاضی دیگر