Senior Penetration Tester, Android Security (Mountain View)
Samsung Research America, Mountain View
The Development Quality Innovation(DQI) lab in Mountain View has a dual role that is first to research new automation tools as well as take current tools and refine them to our needs. Second, act as a centralized QA group to provide quality assessment by creating comprehensive E2E test strategy for various Endpoint security solution developed.
This duality provides a unique opportunity to explore new concepts in different technologies and perform original research in quality domain.
We are looking for a Senior Penetration Tester, that conducts pre-authorized simulated attacks on our groundbreaking B2B enterprise products and services to test system resilience.
In this role, you will conduct offensive security operations to emulate adversary tactics and procedures to test preventative, detective, and response controls across the global technology landscape. You will use your expertise to help influence technology decisions and work as part of a team to create consistent approaches to the offensive security processes and techniques.
Our ideal candidate is a creative thinker and an excellent communicator who is comfortable working in a demanding, fast-paced environment. If you have a passion for security and a strong understanding of the latest technologies, we want to hear from you!
Position Responsibilities:
- Develop expertise in our product solutions, deep diving into design/architecture, & execute white box and black box penetration scenarios
- Plan, scope and conduct vulnerability assessment/ Penetration test on internal / external facing public assets such as Android platform, Android Apps, Backend APIs, and Cloud services
- Research and conduct adversary simulation for known security threats and identify novel attack vectors to test a systems relative security readiness
- Conduct Threat modelling, Threat Intelligence and scoping with stakeholders
- Assist in creating and maintaining internal penetration testing and practice within QA team
- Build Test harness & required Automation suites and validate attack vectors in Threat Lab
- Creating and targeting journals publications on security research
- Vulnerability logging and tracking until closure
- Co-ordinate with program management, security architects at Internal & offshore sites to present the plan, strategy and reports
- Stays up to date on current tools, technologies, and vulnerabilities to incorporate into testing practices
- Research and developing exploits for zero-day vulnerabilities
Required Skills:
- Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent combination of education training and experience
- 5+ years experience in Penetration testing including with 2+ year experience in Android
- Comprehensive knowledge in Information Security practices on malware, phishing attacks, attack vectors and methods to protect against threats
- Extensive Knowledge in Java ,Kotlin or C or any relevant programming language
- Experience with reverse engineering tools (e.g. IDA Pro & Ghidra) , debugging tools(e.g. JTAG/SWD)
- Strong communications, documentation and reporting skills
Special Attributes:
- Experience in Endpoint security platforms
- History in cyber security competitions or CTFs
- Blogpost on security research, walkthroughs or PoCs on security domain
- Malware development or reverse engineering experience
- Experience testing Endpoint Detection & Response (EDR), Extended Detection & Response (XDR) platforms, Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR) or related products
- Cyber Security or Security relevant disciplines
- Certifications in offensive security: OSCP or OSWA or OSWE or CRTO or BSCP or similar
Base Pay Range
$158,800 - $218,100 USD
Additional Information
Disclosure of Trade Secrets
Samsung has a strict policy on trade secrets. In applying to Samsung and progressing through the recruitment process, you must not disclose any trade secrets of a current or previous employer.
Essential Job Functions
This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, and frequently operate standard office equipment, such as telephones and computers.
Samsung Research America is committed to complying with all Federal, State and local laws related to the employment of qualified individuals with disabilities. If you are an individual with a disability and would like to request a reasonable accommodation as part of the employment selection process, please contact the recruiter or email
At Samsung, we believe that innovation and growth are driven by an inclusive culture and a diverse workforce. We aim to create a global team where everyone belongs and has equal opportunities, inspiring our talent to be their true selves. Together, we are building a better tomorrow for our customers, partners, and communities.
Samsung Research America is committed to employing a diverse workforce, and provide Equal Employment Opportunity for all individuals regardless of race, color, religion, gender, age, national origin, marital status, sexual orientation, gender identity, status as a protected veteran, genetic information, status as a qualified individual with a disability, or any other characteristic protected by law.
For more information regarding protection from discrimination under Federal law for applicants and employees, please refer to this link: Pay Transparency
Apply for this job
*
indicates a required field
First Name *
Last Name *
Email *
Phone *
Location (City) *
Resume/CV *
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
LinkedIn Profile
Website
How did you hear about this job? * Select...
Please specify details from your answer above (example: job board name, employee referrer's name, etc.) *
Are you legally authorized to work in United States of America for Samsung Research America? * Select...
Do you now, or will you in the future, require sponsorship for employment visa status (e.g., H-1B visa status) to work legally for Samsung Research America in United States of America? * Select...
Additional Information for California Residents: * Select...
Information about what we are doing to meet the obligations of the California Consumer Privacy Act (CCPA) and California Consumer Privacy Rights Act (CPRA) other important information for California residents is available at SRAs Job Applicant Privacy Policy . Please review the policy carefully, and if you agree to the collection, processing, use, and transfer of your personal information as described in the policy, please indicate your acceptance by selecting Accept from the following drop down menu.
Voluntary Self-Identification
For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.
As set forth in Samsung Research Americas Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.
If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:
A disabled veteran is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.
A recently separated veteran means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.
An active duty wartime or campaign badge veteran means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
An Armed forces service medal veteran means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military opera