Free cookie consent management tool by TermsFeed Senion Penetration Tester : Endpoint Client Security | Antal Tech Jobs
Back to Jobs
2 Weeks ago

Senion Penetration Tester : Endpoint Client Security

decor
Pune, Maharashtra, India
Information Technology
Full-Time
Qualys

Overview

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Job Description:

We are seeking a skilled Penetration Tester to assess and enhance the security of our cross-platform executable Qualys Cloud Agent.

This agent is responsible for system monitoring, data collection, and secure communication with a cloud platform.

Operating across Unix, Windows, and macOS environments, the agent plays a critical role in our security and compliance solutions.

The ideal candidate will uncover vulnerabilities, simulate attack scenarios, and work with our teams to fortify the system against threats.

Key Responsibilities:

Cross-Platform Agent Testing:

  • Conduct comprehensive security testing of the executable agent, ensuring robust functionality across Unix/Linux, Windows, and macOS platforms.
  • Identify and exploit vulnerabilities in the agent’s runtime behavior, system interactions, and interprocess communications.
  • Test agent privilege management and evaluate risks of escalation or exploitation.


Data Collection and Handling:

  • Analyze the agent’s data collection mechanisms to ensure data privacy and integrity.
  • Validate proper implementation of sensitive data redaction and secure storage practices.


Communication Security:

  • Test the agent’s secure communication mechanisms with the cloud server, focusing on:
    • Encryption (TLS/SSL, public key cryptography).
    • Authentication and session management.
    • Mitigation of threats like MITM, replay attacks, and DNS spoofing.


Reverse Engineering and Exploitation:

  • Perform binary analysis to identify vulnerabilities in the agent's implementation.
  • Reverse engineer agent components to assess the effectiveness of tamper-proofing mechanisms and embedded security features.
  • Simulate advanced threat scenarios, including code injection and runtime manipulation.


System Security Evaluations:

  • Assess the agent’s impact on host system security, ensuring it does not inadvertently introduce risks (e.g., open ports, exploitable configurations).
  • Evaluate installation, update, and self-defense mechanisms for tamper resistance and exploitation risks.


Reporting and Remediation:

  • Provide detailed vulnerability reports with proof of concept (PoC), risk impact assessments, and actionable remediation steps.
  • Collaborate with development team to address vulnerabilities and validate fixes
  • Contribute to improving secure development practices and robust agent design.


Required Qualifications:

Technical Expertise:

  • In-depth knowledge of penetration testing methodologies for executable agents, system processes, and OS-specific security models (Windows, Unix/Linux, macOS).
  • Proficiency in network security and cryptographic protocol testing.
  • Strong background in reverse engineering tools and techniques


Tools & Scripting:

  • Scripting skills in Python, Bash, PowerShell, for creating custom tests.
  • Hands on experience with proxy solutions ex Burp or Fiddler


Experience:

  • Proven track record of assessing software agents or similar system monitoring tools.
  • Familiarity with common vulnerabilities, including CVEs related to agent-based applications.
  • Experience working with security tools or platforms similar to Qualys Agent.


Certifications (Preferred):

  • OSCP, OSWE, CEH, GPEN, or equivalent cybersecurity certifications.
  • Relevant cloud certifications such as AWS Security Specialty, Azure Security Engineer Associate.


Preferred Qualifications:

  • Hands-on experience with agent technologies similar to Qualys Cloud Agent.
  • Familiarity with cloud architecture, APIs, and integration points.
  • Knowledge of secure coding practices and defensive programming.
  • Experience with CI/CD pipeline security.
Share job
Similar Jobs
View All
1 Day ago
QA Engineer – Mobile Gaming
Information Technology
  • Vishakhapatnam, Andhra Pradesh, India
About BeBettaBeBetta is a gamified reward platform designed for gamers and entertainers. We’re a mobile-first company growing quickly, with new features launching every week. Our mission is to transform how creators and users engage in the digital s...
decor
1 Day ago
DeepTek.ai - DevOps Engineer - Ansible/Terraform
Information Technology
  • Vishakhapatnam, Andhra Pradesh, India
Job Description : 1- 3 years of hands-on experience with AWS services (EC2, VPC, IAM, S3, CloudWatch, etc.)Required Skills Design and manage secure, scalable, and highly available AWS infrastructure. Deploy and manage containerized workloads using...
decor
1 Day ago
Data Scientist
Information Technology
  • Vishakhapatnam, Andhra Pradesh, India
About LoyalyticsLoyalytics is a fast-growing Analytics consulting and product organization based out of Bangalore.We work with large retail clients across the globe helping them monetize their data assets through our consulting assignments and produ...
decor
1 Day ago
Scrum master/ Senior Consultant Specialist
Information Technology
  • Vishakhapatnam, Andhra Pradesh, India
Job DescriptionSome careers shine brighter than others.If you’re looking for a career that will help you stand out, join HSBC, and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new...
decor
1 Day ago
Python Developer - Django
Information Technology
  • Vishakhapatnam, Andhra Pradesh, India
Job Title : Python Django Developer (3 Years Experience)Location : [Your Location / Remote / Hybrid]Job Type : [Full-time / Contract / Part-time]Experience : 3+ YearsAbout The RoleWe are looking for a skilled and motivated Python Django Develope...
decor
1 Day ago
IT - SDWan Engineer
Information Technology
  • Vishakhapatnam, Andhra Pradesh, India
Syensqo is all about chemistry. We’re not just referring to chemical reactions here, but also to the magic that occurs when the brightest minds get to work together. This is where our true strength lies. In you. In your future colleagues and in all ...
decor
1 Day ago
Senior UI Developer - React.js/AngularJS
Information Technology
  • Vishakhapatnam, Andhra Pradesh, India
Job Description : UX Developer.Location : Pune, India, Remote.Experience : 3-5 years.Job Type : the Role : We are seeking a talented UI/UX Developer with 35 years of experience to join our product engineering team.The ideal candidate will have a...
decor
1 Day ago
Motorola Solutions - Frontend/UI Developer - AngularJS
Information Technology
  • Vishakhapatnam, Andhra Pradesh, India
Department OverviewThe Cloud Platform Engineering team is responsible for : Design and implementation of the continuous integration/continuous delivery (CI/CD) pipeline into multiple public cloud regions Development and operation of common platfor...
decor

Talk to us

Feel free to call, email, or hit us up on our social media accounts.
Social media