penetration tester in iGaming

HireHi

United States

Remote

USD 110,000 - 180,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Оплачиваемый отпуск
Больничные
Возможность профессионального роста
Поддерживающая среда

Job summary

HireHi ищет опытного специалиста по кибербезопасности для проведения тестирования на проникновение и оценки защищенности в условиях высоких нагрузок. Вы будете работать над анализом веб‑приложений, API, инфраструктуры и облака AWS, а также участвовать в красной команде и моделировании угроз.

Требуются 4+ года опыта, OSCP или эквивалентная сертификация, владение Python и Bash, знание Kubernetes, Terraform и CI/CD.

Qualifications

  • 4+ лет опыта в тестировании на проникновение или offensive security.
  • Практический опыт в трех областях: веб-приложения/APIs, внутренняя сеть, внешняя инфраструктура, облако AWS/GCP или мобильные приложения.
  • Наличие OSCP или эквивалентной сертификации по offensive security.
  • Знание MITRE ATT&CK, OWASP ASVS/WSTG, PCI DSS, ISO 27001, NIST и GDPR.

Responsibilities

  • Планирование и проведение пентестов по веб-приложениям, API, мобильным приложениям и облаку AWS.
  • Проведение red team и упражнений на проникновение с эскалацией привилегий и эксфильтрацией данных.
  • Оценка облачных сервисов, Kubernetes и CI/CD пайплайнов; поддержка secure-by-design.
  • Разработка скриптов и инструментов для расширения возможностей тестирования.
  • Работа с командами продукта, инженерии, платежей и мошенничества для приоритизации находок.
  • Отчетность, документация и коммуникация с стейкхолдерами.

Skills

Penetration testing
Cloud security
Python
Bash scripting
English (Upper-Intermediate)

Education

OSCP or equivalent offensive security certification

Tools

Kubernetes
Terraform
Helm
CloudFormation
GitLab/GitHub Actions/Jenkins
SAST/DAST tools

Job description

Описание

The team strengthens the security of high-load products by identifying vulnerabilities across applications, infrastructure, cloud environments, and payment flows. It improves security through offensive security assessments and practical remediation in collaboration with engineering, product, fraud, and compliance teams.

Задачи
  • Plan and execute penetration tests across web applications, APIs, mobile applications, internal and external infrastructure, and AWS cloud environments
  • Perform red team and assumed-breach exercises covering privilege escalation, lateral movement, persistence, and data exfiltration
  • Assess the security of cloud-native services, Kubernetes environments, microservices, and CI/CD pipelines
  • Identify vulnerabilities affecting payment systems, wallets, KYC/AML processes, bonus mechanisms, affiliate tracking, and other business-critical workflows
  • Work with Product, Engineering, AppSec, Payments, and Fraud teams to prioritize findings and support remediation
  • Develop custom scripts and internal tools to improve testing capabilities where standard solutions are insufficient
  • Contribute to threat modeling and support secure-by-design initiatives
  • Review penetration testing plans and reports, and provide technical guidance to junior and middle security specialists
  • Research emerging vulnerabilities, MITRE ATT&CK techniques, and security advisories, and translate them into actionable improvements
  • Support security assessments for new products, releases, and market launches, including effort estimation and pre-certification activities
  • Advise technical and business stakeholders on offensive security matters
Требования
  • 4+ Years of hands-on experience in penetration testing or offensive security
  • Practical experience in at least three areas: web applications/APIs, internal networks, external infrastructure, cloud environments (AWS/GCP), or mobile applications (iOS/Android) OSCP or an equivalent offensive security certification
  • Strong knowledge of SAST, SCA, DAST, AWS/GCP, MITRE ATT&CK, OWASP ASVS, OWASP WSTG, and PTES
  • Good understanding of application architecture, including MVC and data flow principles
  • Knowledge of supply chain attack techniques
  • Experience writing scripts in Python and Bash
  • Understanding of IAM models within at least one major cloud provider
  • Hands-on experience testing Kubernetes-based environments, cloud-native applications, CI/CD pipelines (GitLab, GitHub Actions, Jenkins), and Infrastructure as Code solutions (Terraform, Helm, CloudFormation)
  • Strong reporting, documentation, and communication skills
  • Ability to balance security priorities with business and release deadlines
  • Solid understanding of security frameworks and compliance standards, including PCI DSS, ISO 27001, NIST, and GDPR
  • Upper-Intermediate English
  • Будет плюсом: advanced offensive security certifications such as OSWE, OSEP, OSED, CRTO, BSCP, ARTE, or GRTE; experience designing secure architectures for Kubernetes and AWS environments; previous background in iGaming, fintech, or payment products; public security research, CVEs, advisories, technical publications, or conference presentations; completion of HTB Pro Labs or strong CTF achievements; contributions to open-source offensive or defensive security projects
Условия
  • Competitive salary based on experience
  • Paid annual leave and sick leave
  • Opportunities for professional and career growth
  • Supportive environment focused on continuous development and long-term growth
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

penetration tester in cybersecurity
penetration tester in cybersecurity

HireHi • United States

Remote
USD 120,000 - 160,000
Private health insurance
Performance-based bonus
Professional training portal access
+2
Penetration Tester — iGaming & Payments Security
Penetration Tester — iGaming & Payments Security

HireHi • United States

Remote
USD 110,000 - 180,000
Оплачиваемый отпуск
Больничные
Возможность профессионального роста
+1
application security engineer in fintech
application security engineer in fintech

HireHi • United States

Remote
USD 110,000 - 150,000
Гибкий график работы
Поддержка благополучия (Wellbeing)
Возможности карьерного роста
+1
Application Security Engineer
Application Security Engineer

Enjoy Gaming LLC • United States

Hybrid
USD 120,000 - 190,000
Salary in EUR
Remote work
Medical insurance
+3
security engineer for HR technology
security engineer for HR technology

HireHi • United States

Remote
USD 150,000 - 210,000
Annual training budget
Pension plan
Travel reimbursement
+3
Penetration Tester
Penetration Tester

CGVantage • United States

On-site
USD 110,000 - 170,000
Penetration Tester - Infrastructure & Red Team
Penetration Tester - Infrastructure & Red Team

Cybersecurity Jobs • Miami (FL)

Hybrid
USD 90,000 - 130,000
Education reimbursement
Volunteer day
Birthday day off
+2
security engineer in fintech
security engineer in fintech

HireHi • United States

Remote
USD 120,000 - 210,000
Relocation to Cyprus
Learning and development budget
Fully paid vacation and sick leave
+1
security engineer for financial and payment data
security engineer for financial and payment data

HireHi • United States

Hybrid
USD 110,000 - 150,000
Relocation support to company hubs
Flexible work from offices or remote
Healthcare coverage
+3
qa engineer (manual) for cybersecurity products
qa engineer (manual) for cybersecurity products

HireHi • United States

Remote
USD 65,000 - 100,000
Paid time off and sick leave
Direct impact on a large-scale globalB