TP-Link Systems Inc.→
Penetration Tester, Web/Mobile Apps and Cloud… at TP-Link… · Irvine
Entry LevelOn-siteFull-timeIrvine, CA$80k–$132k/yr
Skills
penetration testingweb application securitycloud securityapi securityowasp top 10security tools - burp suitesecurity tools - owasp zapsecurity tools - nmapsecurity tools - kalisecurity tools - nessussecurity tools - metasploitsast analysisprogramming - pythonprogramming - javascriptprogramming - bashprogramming - powershellcloud platforms - awscloud platforms - azurecloud platforms - gcpsecurity certifications - cehsecurity certifications - oswpwillingness to learnteam-oriented mindset
Job Description
Summary: TP-Link Systems Inc. is a global provider of reliable networking devices and smart home products. They are seeking a skilled and proactive Penetration Tester to support cloud service projects, focusing on penetration testing, threat modeling, and security assessments to enhance the security of their cloud services.
Responsibilities:
- Penetration Testing: Perform penetration testing on cloud services, web applications, and APIs to identify vulnerabilities. Provide remediation recommendations and write detailed penetration test reports
- Threat Modelling and security assessment: Perform threat modeling to identify and evaluate potential risks for specific cloud components and web applications
- Incident Response and Vulnerability Management: Support cloud and web application incident response, including investigation, containment, remediation, and post-incident analysis. Coordinate with cross-functional teams to ensure effective resolution
- Cloud security configuration: Analyze cloud security configurations and identify misconfigurations that could lead to vulnerabilities
- Develop security tools: Assist in developing various pen-testing tools, automated testing platforms, and scripts to enhance testing efficiency and accuracy for cloud environments
- CI/CD Security Integration: Participate in the development and improvement of the company's CI/CD security processes, ensuring security considerations are integrated throughout the development lifecycle
- Interpret cloud security standards and regulatory requirements, supporting implementation of security requirements
Required Qualifications:
- Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent work experience)
- Proven 1-3 years experience as a Security Engineer (Cloud & Web) or in a similar role
- Strong knowledge of web application security, cloud security concepts, API security, and common vulnerabilities (OWASP Top 10)
- Experience with security tools such as Burp Suite, OWASP ZAP, Nmap, Kali, Nessus, Metasploit, etc
- Capability to optimize penetration testing tools and automation strategies for cloud environments
- Ability to analyze SAST results and identify false positives
- Proficient in at least one programming language (e.g., Python, JavaScript, Bash, or PowerShell)
- Familiarity with major cloud platforms (AWS, Azure, GCP) and their security controls
Preferred Qualifications:
- Relevant security certifications (e.g., CEH, OSWP, etc.) are highly preferred
- Published CVEs are highly preferred
Required Skills: Penetration Testing, Web Application Security, Cloud Security, API Security, OWASP Top 10, Security Tools - Burp Suite, Security Tools - OWASP ZAP, Security Tools - Nmap, Security Tools - Kali, Security Tools - Nessus, Security Tools - Metasploit, SAST Analysis, Programming - Python, Programming - JavaScript, Programming - Bash, Programming - PowerShell, Cloud Platforms - AWS, Cloud Platforms - Azure, Cloud Platforms - GCP, Security Certifications - CEH, Security Certifications - OSWP, Willingness to learn, Team-oriented mindset
Benefits: Fully paid medical, dental, and vision insurance (partial premium coverage for dependents), Employer quarterly contributions to 401k funds, 15 days accrued vacation, 11 paid holidays, Bi-annual reviews, and annual pay increases, Health and wellness benefits, including free gym membership, Quarterly team-building event
Benefits
Fully paid medical, dental, and vision insurance (partial premium coverage for dependents)
Employer quarterly contributions to 401k funds
15 days accrued vacation
11 paid holidays
Bi-annual reviews, and annual pay increases
Health and wellness benefits, including free gym membership
Quarterly team-building event