- Location
- IN KA BANGALORE Home Office Building 11, India
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Experience
- 5+ years
- Education
- Bachelor
- Closing date
- Today
- Source
- Workday
Description
Position Summary...
What you'll do...
About Team:
Walmart continues to grow an elite Information Security team and is looking for a talented and experienced Senior Pentest Engineer to join our Cybersecurity Testing practice! Walmart Technology is on the cutting edge of many security issues for a wide variety of platforms and technologies including cloud services, Internet of things (IoT), identity and access management, mobile devices, virtualization, AI and Robotics, and custom hardware, all operating at massive scale and if you want to be a part of the Information Security team that develops innovative solutions that balance security and business priorities, this is the job for you! As an Senior Engineer, you will be expected to be strong in multiple domains and provide significant contributions to the Walmart Information Security team and to multiple groups throughout Walmart. You will be responsible for identifying exploitable security vulnerabilities in IoT, embedded devices, cloud-based technologies and services, mobile solutions, APIs, hardware, firmware, source code and applications, while following security engineering best practices.
What you'll do:
Develop exploits and customized proof of concepts for diverse targets and tech stacks.
Validating Bug Bounty submissions from our private programs partners.
Develop and utilize advanced tools for penetration testing and exploiting vulnerabilities
Research, learn, and continuously improve skills to emulate attacker tactics, techniques, and procedures
Influence technical and business strategies by articulating technical risk associated with key business solutions
Provide security and vulnerability remediation expertise to technology stakeholders and partners
Mentor and share knowledge with other security practitioners and technology stakeholders
Assist in the implementation of advanced security technology solutions by conducting feasibility studies, proof of concept, product comparison, and/or optimization analyses; participating in project artifact and technical reviews; challenging suppliers to improve technology; and researching technology and software development for secure information technology solutions.
Maintain and advances security expertise by reviewing new technologies; maintaining knowledge of current security standards (for example, NIST 800-53, ISO27001, Cloud Security Alliance); participating in continuing education and training (for example, relevant industry certifications, forums); and maintaining expert level knowledge of enterprise technologies.
What you'll bring:
8+ years Information Security experience
5+ years expert experience executing penetration testing/ethical hacking against IoT, embedded systems, cloud-based technologies, mobile, hardware, APIs, web applications
Advanced-level experience security testing in dynamic enterprise cloud environments
Strong technical knowledge around web application security: ability to identify and reproduce reported vulnerabilities, as well as assess contextual risk.
In-depth knowledge of security fundamentals, including OWASP Top 10 and other common application security vulnerabilities. The Web Application Hacker’s Handbook is a great resource to be familiar with.
Possess one or more of these credentials: OSCP, OSWE, GXPN, GWAPT, GPEN, CREST CRT, OSCP, HTB CPTS etc.
Familiarity with and ability to calculate CVSS ratings for identified vulnerabilities based on an understanding of each customer’s threat model.
Familiar with vulnerability disclosure and bounty programs, including: confidentiality and disclosure processes, the importance of clear and quick communication between hackers and customers, program policies, etc.
Ability to prioritize and organize operationally complex work, with great attention to detail.
Strong ability to identify and exploit security gaps/vulnerabilities on endpoint devices, applications and networks.
Exposure and understanding of enterprise solutions from a functional and security perspective.
Preferred bug bounty experience
Preferred development skills (be able to understand the issue from a dev perspective and discuss fix with dev teams).
Top notch communication skills: need to be able to firmly, yet politely, respond to non-issues, as well as identify legitimate issues and communicate them to security teams in an easy to understand format. And ability to articulate and translate security and risk management terminology in business terms.
About Walmart Global Tech
Imagine working in an environment where one line of code can make life easier for hundreds of millions of people. That’s what we do at Walmart Global Tech. We’re a team of software engineers, data scientists, cybersecurity expert's and service professionals within the world’s leading retailer who make an epic impact and are at the forefront of the next retail disruption. People are why we innovate, and people power our innovations. We are people-led and tech-empowered.
We train our team in the skillsets of the future and bring in experts like you to help us grow. We have roles for those chasing their first opportunity as well as those looking for the opportunity that will define their career. Here, you can kickstart a great career in tech, gain new skills and experience for virtually every industry, or leverage your expertise to innovate at scale, impact millions and reimagine the future of retail.
Mode of Work
Walmart’s culture sets us apart, and we know being together helps us innovate, learn and grow great careers. This role is based in our Bangalore office for daily work, with the flexibility for associates to manage their personal lives.
Benefits
Beyond our great compensation package, you can receive incentive awards for your performance. Other great perks include a host of best-in-class benefits maternity and parental leave, PTO, health benefits, and much more.
Belonging
We aim to create a culture where every associate feels valued for who they are, rooted in respect for the individual. Our goal is to foster a sense of belonging, to create opportunities for all our associates, customers and suppliers, and to be a Walmart for everyone.
At Walmart, our vision is "everyone included." By fostering a workplace culture where everyone is—and feels—included, everyone wins. Our associates and customers reflect the makeup of all 19 countries where we operate. By making Walmart a welcoming place where all people feel like they belong, we’re able to engage associates, strengthen our business, improve our ability to serve customers, and support the communities where we operate.
Equal Opportunity Employer
Walmart, Inc., is an Equal Opportunities Employer – By Choice. We believe we are best equipped to help our associates, customers and the communities we serve live better when we really know them. That means understanding, respecting and valuing unique styles, experiences, identities, ideas and opinions – while being inclusive of all people
Minimum Qualifications...
Outlined below are the required minimum qualifications for this position. If none are listed, there are no minimum qualifications.
Option 1: Bachelor's degree in computer science, information technology, engineering, information systems, cybersecurity, or related area and 3years’ experience in penetration testing or related area at a technology, retail, or data-driven company. Option 2: 5 years’ experience in penetration
testing or related area at a technology, retail, or data-driven company.
Preferred Qualifications...
Outlined below are the optional preferred qualifications for this position. If none are listed, there are no preferred qualifications.
Certifications in Security+, Network+, GISF, GSEC, CISSP, CCSP, or GPEN., Master’s degree in computer science, information technology, engineering, information systems, cybersecurity, or related area and 1 year’s experience leading information security or cybersecurity projects.