Application Security Test Engineer - (Thick Client Penetration Testing + Source Code Review)
SonicWall is a cybersecurity forerunner with more than 30 years of expertise and is recognized as a leading partner-first company, ensuring our partners and their customers are never alone in the fight against cybercrime. With the ability to build, scale and manage security across the cloud, hybrid and traditional environments in real-time, SonicWall provides relentless security against the most evasive cyberattacks across endless exposure points for increasingly remote, mobile and cloud-enabled users. With its own threat research center, SonicWall can quickly and economically provide purpose-built security solutions to enable any organization—enterprise, government agencies and SMBs—around the world. For more information, visit www.sonicwall.com or follow us on Twitter, LinkedIn, Facebook and Instagram.
Location: Remote ( Only for the candidates residing in Costa Rica)
Job Description:
We are seeking a skilled Application Security Test Engineer - (Thick Client Penetration Testing + Source Code Review)' to join our security team. In this role, you will be responsible for conducting security assessments, penetration testing, and secure code reviews of our thick client applications across various platforms (Windows, Linux desktop applications and mobile clients). Your primary focus will be on identifying and mitigating security vulnerabilities to enhance the overall security posture of our applications and services.
Responsibilities:
• Conduct thorough vulnerability assessment on the Windows desktop VPN, other client applications and mobile client apps (Android and iOS).
• Identify and analyze cryptographic algorithms, protocols, and identify security misconfigurations implemented in the applications.
• Perform manual penetration testing to identify vulnerabilities, weaknesses, and potential exploits in the VPN and SonicWall client applications.
• Utilize various tools and methodologies to conduct static and dynamic security analysis of the binary code.
• Review source code for security flaws, coding errors, and potential areas of improvement.
• Collaborate with the development team to provide recommendations for secure coding practices.
• Conduct penetration testing on the Firewall hardware, virtual appliances, and VPN client applications to simulate real-world attack scenarios.
• Document and report findings, including recommended remediation steps.
• Stay abreast of the latest cybersecurity threats, vulnerabilities, and attack vectors relevant to VPN technologies.
• Prepare comprehensive reports detailing the results of security assessments and penetration tests.
• Clearly communicate findings, risks, and recommended mitigations to both technical and non-technical stakeholders.
• Works closely with cross-functional teams, including developers, system administrators, and PSIRT engineers, to address and resolve security issues.
Qualifications:
• Bachelor's degree in computer science, Cybersecurity, or a related field.
• Proven experience in Windows, Linux desktop applications and mobile clients (Android and iOS).
• Proficiency in using tools such as Burp Suite, Wireshark, IDA Pro, Ghidra, and other relevant application security tools.
• Strong understanding of VPN technologies, cryptographic protocols, and network security principles.
• Experience with Security Testing methodologies and standards.
• Excellent written and verbal communication skills.
• Certifications such as OSCP, OSCE, or similar are a plus.
#LI-KB7
#LI-Remote
#securitytesting #penetrationtester #sourcecodeanalyst
SonicWall is an equal opportunity employer.
We are committed to creating a diverse environment and are an equal opportunity employer. All qualified applicants receive consideration for employment without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.
At SonicWall, we pride ourselves on recruiting a diverse mix of talented people and providing active security solutions in 100+ countries.
Apply for this job
*
indicates a required field