Vertiv logo
VertivPosted 1 month ago

Application and Product Security I Analyst I

On-sitePune, Maharashtra, India

Full TimeLargeData Center Services

Job Summary

Conduct security evaluations, threat assessments, and penetration testing on embedded systems, mobile apps, and web applications by circumventing protection methods, performing data bus monitoring, and analyzing communications protocols. Research new vulnerabilities, reverse engineer complex systems, and execute black box engagements to identify design weaknesses. Create detailed technical reports, proof of concept code, and project breakdowns to document findings and coordinate testing activities with senior engineers. Provide proactive analysis reports on testing progress and status to respective engineering groups. This role is based in Pune, India, under the guidance of the global security team.

Required Qualifications

  • Bachelor's degree in information technology, Computer Science or related field
  • Two or more years of experience (2+ years) in information, application, embedded product security and/or IT risk management with a focus on security, performance, and reliability
  • Solid understanding of security protocols, cryptography, authentication, authorization and security
  • Good working knowledge of current IT risks and experience implementing security solutions
  • Ability to interact with a broad cross-section of personnel to articulate and enforce security measures
  • Excellent written and verbal communication skills as well as business acumen
  • Strong ability to establish partnerships and influence change and achieve results within dynamic environment
  • Meaningful technical contributions into the development lifecycle of an application, product or service
  • Understanding and development experience of embedded systems / software, and web-based applications
  • Linux network device driver/data-path performance exposure
  • Familiarity with compilers, debuggers, disassemblers, and other low-level development and analysis tools
  • Exposure to binary analysis tools such as IDA Pro, WinDbg, BinWalk, Valgrind, PIN, Panda and S2E
  • Working knowledge of hacking tools and techniques such as memory corruption exploits, rootkits, protocol poisoning, browser-based attacks, DNS poisoning, MetaSploit, nmap, Nessus, etc.
  • An understanding of common cryptographic algorithms and protocols including their weaknesses and attacks against them
  • Understanding of network protocols and experience developing packet-level programs
  • Understanding of common microcontroller programming tools and debugging interfaces
  • Exposure to Layer 2, Layer 3 networking, QoS
  • Knowledge of common malware/botnet exploits and how they are targeted to exploit embedded systems
  • Operating system configuration of Windows, Linux, Android, and iOS
  • Computer boot process including boot loaders

Desired Qualifications

  • Additional advanced security qualifications such as OSCP (Offensive Security Certified Professional) certification, CEH (Certified Ethical Hacker) or equivalent
  • Use of Gitlab for issue management, tool usage experience preferred
  • Preference given to other practical skills such as: functional analysis, memory image capture, static memory analysis, and data element extraction, etc.
  • A bachelor's degree in information technology, Computer Science or related field is highly desirable

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce