Associate Security EngineerBrainstation-23
Dhaka,Bangladesh
Pre-Sales Engagement Support — Assist the sales and business development teams during pre-sales activities for penetration testing engagements, including scoping discussions, effort estimation, technical proposal preparation, and client consultation calls.Client Web Application Penetration Testing — Plan, execute, and deliver comprehensive penetration testing engagements on client web applications, identifying vulnerabilities, validating exploitability, and providing clear remediation guidance through professional reports.Multi-Methodology Security Testing — Perform black-box, gray-box, and white-box penetration testing across a range of targets, including: Web applicationsRESTful and GraphQL APIsMobile applications on Android and iOS (optional, based on project needs)Vulnerability Identification & Validation — Discover, exploit, and document security weaknesses aligned with industry-standard frameworks such as the OWASP Top 10, OWASP API Security Top 10, and OWASP Mobile Top 10.Remediation & Re-Testing Support — Collaborate closely with development and DevSecOps teams throughout the remediation lifecycle, providing technical guidance, validating fixes, and conducting re-tests to confirm vulnerabilities have been properly resolved.Creative & Adversarial Thinking — Go beyond traditional testing checklists by adopting an attacker's mindset — exploring business logic flaws, chained exploits, and unconventional attack paths that automated tools and standard methodologies often miss.Research & Internal Enablement — Actively track emerging threats, newly disclosed CVEs, and evolving attack techniques across web and mobile ecosystems, and apply those insights to continuously improve Brainstation-23's internal penetration testing playbooks, methodologies, and checklists.
Hands-On Offensive Security Experience — 2–4 years of professional penetration testing experience covering web applications, RESTful/GraphQL APIs, and ideally mobile platforms (Android/iOS), with practical command of black-box, gray-box, and white-box methodologies and deep familiarity with the OWASP Top 10, OWASP API Top 10, and OWASP Mobile Top 10.Technical Toolkit & Scripting — Proficiency with industry-standard tools such as Burp Suite Pro, OWASP ZAP, Postman, Frida, MobSF, and Nmap, combined with scripting ability in Python, Bash, or JavaScript for custom payloads, exploit development, and automation. Solid grasp of core networking and web protocols (TCP/IP, DNS, HTTP/HTTPS, TLS).Reporting, Collaboration & Pre-Sales Support — Ability to produce clear, professional penetration test reports with accurate risk ratings and actionable remediation guidance, while collaborating effectively with development and DevSecOps teams during remediation and re-testing. Comfortable supporting pre-sales activities including scoping, effort estimation, and technical proposal input.Adversarial Mindset & Continuous Learning — Demonstrated ability to think beyond checklists — chaining vulnerabilities, identifying business logic flaws, and uncovering issues automated scanners miss — paired with a genuine passion for staying current with emerging threats, newly disclosed CVEs, and evolving attack techniques across web and mobile ecosystems.
Deadline:Closed

