【日商樂天】Penetration Tester (DU)

09/24更新
5 天內聯絡過求職者
應徵

工作內容

In Rakuten Group, the security and safety of the Internet services are guaranteed by the Cyber Security Defense Department (CSDD). CSDD covers all aspects of the System Development Life Cycle (SDLC) and operation security for all the services developed inside Rakuten Group. As a member of CSDD Security Audit Group, you will execute offensive security activities and penetration tests against the wide variety of systems and will be challenged to various projects in different aspect of security while working with other peer engineers. Expected tasks ranging from but not limited to finding security vulnerabilities, writing scripts to automate security tasks, enhance the network security of Rakuten infrastructure, and provide remediation suggestions. You will develop novel attack techniques against new and existing products & deliver high-quality risk reporting outputs for stakeholders across Rakuten group companies. 【Key responsibilities】 •Planning, execution, and quality control of security testing and adversary emulation engagements •Develop attack vectors, conduct reconnaissance, collect open-source intelligence, enumerate target networks and services, develop and execute exploits, and deliver payloads to demonstrate mission impact •Demonstrate the risk, document findings, and provide remediation recommendations and mitigation strategies •Develop and present accurate and comprehensive reports for both non-technical and technical audiences including leadership •Contribute to the development of automated tools and procedures to maximize efficiency in Red Team services •Stay informed of new and emerging adversary TTPs, and evaluate their impact on Rakuten Group. •Support Vulnerability Assessment of Rakuten products (by both manual test & DAST) •Evaluate and integrate security software solutions •Perform technical analysis, testing, or demonstrate the security threats in simple POCs •Support development teams as a technical consultant •Working alongside other engineers and stakeholders to deliver global projects and initiatives 【Mandatory qualifications】 •Minimum 4 years of experience in IT/Information Security related fields •2+ years of experience in Web/Mobile/Network Penetration Testing and/or Vulnerability Assessment •Understanding of the core concepts of web/mobile application and security issues •Proficient in one or more scripting languages, ex: Python, Ruby •Proven knowledge of network and web application protocols •Familiarity and knowledge of Active Directory concepts •Strong teamwork capability in a diverse team environment •Ability to work in a highly diverse environment 【Desired qualifications】 •Experience in Web/Mobile application development •Experience in using major web frameworks •Experience with red teaming and common TTPs (Tactics, Techniques and Procedures) •Experience with at least one major commercial cloud environment •Experience in a diverse workplace, and work well in a team environment •Holder of any security-related certifications, ex: OSCP/OSCE, CISSP •Strong verbal and written communications skill •Strong ownership and sense of responsibility

工作待遇

待遇面議

(經常性薪資達 4 萬元或以上)

工作性質

全職

上班地點

台北市中山區民生東路三段49號11樓 (距捷運中山國中站約500公尺)

管理責任

不需負擔管理責任

出差外派

無需出差外派

上班時段

日班,9:00~18:00

休假制度

週休二日

可上班日

不限

需求人數

1人

條件要求

工作經歷

4年以上

學歷要求

大學以上

科系要求

不拘

語文條件

英文 -- 聽 /精通、說 /精通、讀 /精通、寫 /精通

擅長工具

工作技能

不拘

其他條件

【擅長工具】 BurpSuite, Nessus

歡迎所有求職者,與
應屆畢業生
外籍人士

公司環境照片(5張)

台灣樂天市場股份有限公司 企業形象

福利制度

法定項目

其他福利

• 2022幸福企業-金獎 • 2021幸福企業-金獎 • 2020HR Asia Awards • 壽星最大,生日當月爽放生日假一天 • 到職第一年就享有8天特休假 (依到職比例計算,第2年起11天,當年度休不完還可以延到隔年底) • 自選式福利補助金每年一萬元,讓你彈性選擇使用樂天的服務 • 員工認股計畫,陪著樂天一起成長 • 完善的公司內、外教育訓練課程及海外受訓機會 • 參與跨國專案或國外研討會,培養國際化歷練 • 全球樂天賞機制,獲獎送你免費遊日本 • 年度員工健康檢查,您的健康是樂天最大的幸福 • 飲料/零食販賣機,再忙也會陪你喝杯咖啡 • 辦公室樂活舒壓按摩服務 • 全額補助團保,讓您無後顧之憂

聯絡方式

聯絡人

HR
104人力銀行提醒您履歷關閉時仍可投遞履歷喔!面試時請遵守求職禮儀準時赴約並小心安全
求職安全專線【勞動部】0800-085-151【104人力銀行】02-29126104轉2 或來信詢問
建議使用104內建訊息功能,以保障您的求職權益,職缺內容可能包含第三方通訊軟體,敬請謹慎評估。
職場安全提醒

適合你大展身手的工作

智能客服
您好,我是您的智能客服 找頭鹿有任何問題都可以問我喔!