Job Description

HR Bamboos connects exceptional professionals with reputable organizations across Iran and international markets.

We are seeking an experienced Penetration Test Lead to join our client, a growing e-commerce company, and lead complex security assessments and Red Team engagements across applications, infrastructure, and cloud environments.
This role is ideal for a Penetration Testing Lead with strong expertise in penetration testing, adversary simulation, vulnerability analysis, and security assessment, who is passionate about uncovering realistic attack paths, validating security controls, and strengthening the organization’s overall security posture.

Key Responsibilities
Penetration Testing & Security Assessment
• Lead and execute penetration tests across web and mobile applications, APIs, networks, infrastructure, cloud, Kubernetes, and containerized environments.
• Define assessment scopes, testing methodologies, Rules of Engagement, severity criteria, and reporting standards.
• Conduct hands-on security testing, source code reviews, and vulnerability validation, with a focus on business impact and risk.
• Re-test remediated vulnerabilities and validate the effectiveness of security fixes.

Red Team & Detection
• Design and lead Red Team and adversary simulation exercises to uncover realistic attack paths and validate security controls.
• Collaborate with SOC and Blue Team members to assess and improve detection and response capabilities.
• Support security investigations and contribute to identifying and addressing emerging security risks.

Security Engineering & Reporting
• Partner with Engineering, Development, DevOps, and SRE teams to integrate security testing into the SDLC and CI/CD pipelines.
• Produce clear technical reports with practical remediation guidance and track remediation through to completion.
• Track security and remediation metrics and provide insights to improve security
assessment and remediation processes.

Technical Leadership
• Lead and mentor penetration testing engineers and review findings from internal and external security assessments.
• Maintain assessment quality standards and drive consistency across security testing activities.

What You Bring
• 6+ years of professional experience in penetration testing, offensive security, or a related field.
• Strong skills in web, mobile, API, network, infrastructure, and cloud security testing.
• Strong skills in Red Team operations and MITRE ATT&CK-aligned adversary simulation.
• Strong knowledge of OWASP, vulnerability exploitation, attack-path analysis, threat modeling, and security architecture.
• Strong understanding of Linux and Windows security, authentication, authorization, databases, and middleware.
• Hands-on experience assessing Kubernetes, containerized workloads, and cloud environments.
• Proficiency with offensive security tools such as Burp Suite, Nmap, and Metasploit.
• Strong scripting skills in Python, Bash, or Go for security automation and tooling.
• Hands-on DevSecOps experience with CI/CD security testing, including SAST, DAST, SCA, secret scanning, container scanning, and IaC scanning.
• Strong skills in vulnerability analysis, risk prioritization, and technical security reporting.
• Strong technical leadership, mentoring, and security assessment quality management skills.
• Strong communication, collaboration, and stakeholder management skills across Engineering, Security, DevOps, and leadership teams.

Nice to Have
• Certifications such as OSCP, OSEP, OSWE, GPEN, or similar.
• Experience with Active Directory security, privilege escalation, and lateral movement.
• Experience with tools such as BloodHound, Nessus, SQLMap, Cobalt Strike, or similar platforms.
• Experience conducting cloud security assessments across AWS, Azure, or GCP.

What We Offer
• Competitive compensation and benefits.
• Professional growth and development opportunities.
• The opportunity to lead high-impact security initiatives and strengthen the security posture of a growing e-commerce company.

If you’re looking for a dynamic environment where your ideas, perspective, and contributions can make a meaningful impact on both your professional growth and the organization’s success, we’d love to hear from you.

Apply now

We maintain the highest level of confidentiality throughout the recruitment process.

Employment Type

  • Full Time

Seniority

Details

Employment type

  • Full Time

Seniority

برای مشاهده‌ی شغل‌هایی که ارتباط بیشتری با حرفه‌ی شما دارد،