İnformasiya təhlükəsizliyi sistemlərini inkişaf etdirir və idarə edir, güclü təhlükəsizlik bilikləri tələb olunur.
Vakansiya haqqında
Responsibilities:
- Planning and conducting penetration tests of internal and external infrastructure (network, Active Directory, Windows/Linux servers);
- Security assessment of web applications (OWASP Top 10, business logic vulnerabilities, authentication/authorization flaws);
- Analysis of attack paths in Active Directory environments (Kerberoasting, ACL abuse, delegation vulnerabilities, lateral movement scenarios);
- Assessing identified vulnerabilities based on their risk level and preparing technical and management-level reports;
- Collaborating with infrastructure and application teams during the remediation process and conducting retesting of fixes;
- Working closely with the SOC team to test and improve detection rules;
- Participating in phishing simulations and social engineering assessments;
- Security assessment of AI-based systems and LLM-integrated applications (prompt injection, jailbreak, data leakage, and test scenarios based on the OWASP Top 10 for LLM Applications);
- Effective use of AI-based tools in penetration testing processes (reconnaissance, payload generation, and report preparation automation);
- Managing the vulnerability management process: administration of Rapid7 and Tenable Nessus scanners, configuration of scan profiles, analysis of results, and false-positive filtering;
- Analyzing the impact of new CVEs on the infrastructure and prioritizing them;
- Defining the scope, planning, and leading the execution of penetration testing projects;
- Mentoring team specialists, providing technical guidance, and ensuring the quality of prepared reports;
- Developing and improving penetration testing methodologies, internal standards, and procedures;
- Presenting test results to management and explaining risks in business terms.
Requirements:
- At least 3 years of practical experience in information security, including at least 1 year of practical experience in penetration testing;
- Practical certification requirement: OSCP or an equivalent certification — CRTO, GPEN, or similar. OSEP, OSWE, and CRTE certifications are considered an advantage;
- Ability to independently plan and conduct network and infrastructure penetration tests and lead projects at the project level;
- Practical experience in security assessment of Active Directory environments and a deep understanding of key attack paths;
- Ability to manually test web applications, going beyond automated scan results to identify business logic, authentication, and authorization vulnerabilities;
- Practical experience with vulnerability scanners: configuration of scans, triage, and validation of results using Tenable Nessus, Rapid7 InsightVM/Nexpose, or equivalent solutions;
- Knowledge of post-exploitation, privilege escalation, and analysis of key security configurations in Windows and Linux systems;
- Manual testing of API security, REST and GraphQL APIs, including Broken Object Level Authorization (BOLA/IDOR), mass assignment, and rate limiting bypass;
- Cloud security knowledge, including basic penetration testing scenarios in AWS / Azure / GCP environments (IAM misconfiguration, S3 bucket exposure, metadata service abuse);
- Understanding of security in containerized/microservices environments, including key Docker and Kubernetes misconfiguration points and container escape scenarios;
- Automation of AI-oriented tasks in daily penetration testing activities;
- Proficiency in at least one scripting language for test process automation and, when required, development of simple tools: Python, PowerShell, or Bash;
- Ability to document findings in a clear, reproducible, and risk-based reporting format and provide specific remediation recommendations;
- Experience in technical leadership or mentoring within a team and ability to independently manage complex projects;
- Fluency in Azerbaijani;
- Proficiency in English for working with technical documentation and reports.
Preferred Qualifications:
- Additional certifications: OSEP, OSWE, CRTP/CRTE, BSCP, or equivalent practical certifications;
- Understanding of EDR detection and evasion techniques;
- Understanding of how attacks are reflected from a logging and detection perspective;
- Experience with C2 frameworks: Cobalt Strike, Sliver, Havoc, or equivalent tools;
- Participation in CTFs, HackTheBox/TryHackMe profiles, bug bounty experience, or personal security research, such as blog posts, CVEs, open-source tools, etc.;
- Interest or practical experience in AI/LLM security: OWASP LLM Top 10, MITRE ATLAS, AI red teaming;
- Familiarity with AI-assisted penetration testing tools: PentestGPT, Burp AI, and equivalent solutions
We Offer:
- Meal allowance;
- Annual performance bonuses;
- Corporate health program: Voluntary insurance and special discounts for gyms;
- Access to Digital Learning Platforms.
Note: Only candidates who meet the requirements of the vacancy will be contacted for the next stage.
Interested candidates can send their CV to the e-mail address in the Apply for job button.
Responsibilities:
- Planning and conducting penetration tests of internal and external infrastructure (network, Active Directory, Windows/Linux servers);
- Security assessment of web applications (OWASP Top 10, business logic vulnerabilities, authentication/authorization flaws);
- Analysis of attack paths in Active Directory environments (Kerberoasting, ACL abuse, delegation vulnerabilities, lateral movement scenarios);
- Assessing identified vulnerabilities based on their risk level and preparing technical and management-level reports;
- Collaborating with infrastructure and application teams during the remediation process and conducting retesting of fixes;
- Working closely with the SOC team to test and improve detection rules;
- Participating in phishing simulations and social engineering assessments;
- Security assessment of AI-based systems and LLM-integrated applications (prompt injection, jailbreak, data leakage, and test scenarios based on the OWASP Top 10 for LLM Applications);
- Effective use of AI-based tools in penetration testing processes (reconnaissance, payload generation, and report preparation automation);
- Managing the vulnerability management process: administration of Rapid7 and Tenable Nessus scanners, configuration of scan profiles, analysis of results, and false-positive filtering;
- Analyzing the impact of new CVEs on the infrastructure and prioritizing them;
- Defining the scope, planning, and leading the execution of penetration testing projects;
- Mentoring team specialists, providing technical guidance, and ensuring the quality of prepared reports;
- Developing and improving penetration testing methodologies, internal standards, and procedures;
- Presenting test results to management and explaining risks in business terms.
Requirements:
- At least 3 years of practical experience in information security, including at least 1 year of practical experience in penetration testing;
- Practical certification requirement: OSCP or an equivalent certification — CRTO, GPEN, or similar. OSEP, OSWE, and CRTE certifications are considered an advantage;
- Ability to independently plan and conduct network and infrastructure penetration tests and lead projects at the project level;
- Practical experience in security assessment of Active Directory environments and a deep understanding of key attack paths;
- Ability to manually test web applications, going beyond automated scan results to identify business logic, authentication, and authorization vulnerabilities;
- Practical experience with vulnerability scanners: configuration of scans, triage, and validation of results using Tenable Nessus, Rapid7 InsightVM/Nexpose, or equivalent solutions;
- Knowledge of post-exploitation, privilege escalation, and analysis of key security configurations in Windows and Linux systems;
- Manual testing of API security, REST and GraphQL APIs, including Broken Object Level Authorization (BOLA/IDOR), mass assignment, and rate limiting bypass;
- Cloud security knowledge, including basic penetration testing scenarios in AWS / Azure / GCP environments (IAM misconfiguration, S3 bucket exposure, metadata service abuse);
- Understanding of security in containerized/microservices environments, including key Docker and Kubernetes misconfiguration points and container escape scenarios;
- Automation of AI-oriented tasks in daily penetration testing activities;
- Proficiency in at least one scripting language for test process automation and, when required, development of simple tools: Python, PowerShell, or Bash;
- Ability to document findings in a clear, reproducible, and risk-based reporting format and provide specific remediation recommendations;
- Experience in technical leadership or mentoring within a team and ability to independently manage complex projects;
- Fluency in Azerbaijani;
- Proficiency in English for working with technical documentation and reports.
Preferred Qualifications:
- Additional certifications: OSEP, OSWE, CRTP/CRTE, BSCP, or equivalent practical certifications;
- Understanding of EDR detection and evasion techniques;
- Understanding of how attacks are reflected from a logging and detection perspective;
- Experience with C2 frameworks: Cobalt Strike, Sliver, Havoc, or equivalent tools;
- Participation in CTFs, HackTheBox/TryHackMe profiles, bug bounty experience, or personal security research, such as blog posts, CVEs, open-source tools, etc.;
- Interest or practical experience in AI/LLM security: OWASP LLM Top 10, MITRE ATLAS, AI red teaming;
- Familiarity with AI-assisted penetration testing tools: PentestGPT, Burp AI, and equivalent solutions
We Offer:
- Meal allowance;
- Annual performance bonuses;
- Corporate health program: Voluntary insurance and special discounts for gyms;
- Access to Digital Learning Platforms.
Note: Only candidates who meet the requirements of the vacancy will be contacted for the next stage.
Interested candidates can send their CV to the e-mail address in the Apply for job button.
Şirkət haqqında
SOCAR Tech — SOCAR və onun ekosistemi üçün texnologiya, rəqəmsallaşma və innovasiya sahəsində kompleks həllər təqdim edən texnologiya şirkətidir.
SOCAR Tech — bütün vakansiyalarBacarıqlar və texnologiyalar
Müraciətin
Bacarıqlara görə oxşar
Bütün oxşar vakansiyalarBu vakansiyanın bacarıqları ilə ən çox üst-üstə düşən vakansiyalar.
Süni intellekt və data analitika layihələrini idarə edir, Python və ML bilikləri tələb olunur.
Struktur komandanı idarə edir, texniki rəsmləri yoxlayır və layihə tələblərinə cavab verir.




