ZALORA: Senior Information Security Engineer at ZALORA (Ho Chi Minh City, Vietnam) (Ho Chi Minh City, Vietnam)
Posted: Nov 2, 2021
We’re looking for a SeniorInformation Security Engineer to join our infrastructure team at ZALORA. As an information Security Engineer, you will help build secure software, monitoring system, and infrastructure at the highest security standard. You will perform technical security assessments, code reviews, and vulnerability testing to highlight and mitigate risks. You will work closely with other engineers, audit vendors to design and build a proactive system to enhance the security of our infrastructure and systems.
- Perform technical security assessments, code audits and design reviews.
- Exploit security flaws and vulnerabilities with attack simulations on multiple application platforms like Android, iOS, and Web
- Ability to flow from black box to grey box to white-box tests.
- Ability to effectively work with the engineering teams to provide technical risk. assessment of technologies in networks, applications, code reviews in the release management cycle.
- Ability to perform vulnerability assessments and penetration testing, utilizing tools - commercial and open source.
- Perform, review, and analyze security vulnerability data to identify applicability and false-positives.
- Conduct penetration testing in line with Open Web Application Security Project (OWASP)
- Write technical reports that include suggested resolution for identified problem areas and perform the operational risk assessment.
- Perform information security due diligence during vendor onboarding
- Collaborate with other departments in their daily security requirements.
- BS degree in Computer Science, or a related technical field, or equivalent practical experience.
- OWASP top 10
- Security Pen Testing methodologies including automated scans and manual methods
- Tools including Burp, Nexpose, NMap, Whois etc. is a plus
- 6 years relevant experience
- Experience with security issues in Cloud Technologies (AWS) is a plus
- Ability to grasp new technology concepts quickly
- Good documentation skills
- Ability to work in a team environment and interact with people