我们使用Cookie和类似技术来改善您的体验、分析网站使用情况并协助我们的营销工作。我们收集的数据包括页面访问记录和匿名使用统计。 隐私政策
发布时间:
Company Overview DracoSec Research Limited develops accessible cybersecurity technologies for startups, NGOs, SMEs, and organisations operating in regulated sectors. Our core technology is a command-line and AI-augmented vulnerability assessment platform that consolidates findings from multiple security scanners and transforms complex technical results into clear, prioritised, and actionable reports for both technical teams and management. The platform incorporates vulnerability detection, risk scoring, threat correlation, workflow automation, compliance analysis, and integration with external security tools and threat-intelligence sources. Role Overview We are seeking a Cybersecurity Engineer to support the research, development, and validation of DracoSec's cybersecurity assessment technologies. The successful candidate will focus on penetration testing, vulnerability research, secure code review, automated security-tool development, and the improvement of DracoSec's vulnerability detection and reporting capabilities. The role will involve conducting applied cybersecurity research and converting research findings into practical testing methods, prototypes, detection logic, and platform enhancements. Key Responsibilities Penetration testing and security assessments for web applications, APIs, and mobile applications across financial, retail, technology, and enterprise environments. Research emerging vulnerabilities, attack techniques, exploitation methods, and application-security risks to improve DracoSec's security-testing methodologies and detection capabilities. Develop and enhance automated security-testing tools, scripts, vulnerability-validation modules, and secure code-review frameworks. Conduct manual validation of scanner findings, assess the exploitability and potential impact of identified vulnerabilities, and reduce false-positive and false-negative results. Review source code, application architecture, and system configurations to identify authentication, access-control, input-validation, business-logic, and security-configuration weaknesses. Prepare technical research and assessment reports detailing identified vulnerabilities, supporting evidence, risk levels, attack scenarios, remediation recommendations, and follow-up testing results. Requirements Bachelor's degree or above in Information Security, Cybersecurity, Computer Science, Software Engineering, Information Technology, Electronic Engineering, or a related STEM discipline. Relevant experience in penetration testing, vulnerability assessment, application security, cybersecurity research, secure code review, or security engineering. Strong knowledge of web, API, mobile, network, cloud, and application-security vulnerabilities. Hands-on experience with penetration-testing methodologies, vulnerability scanners, security-testing tools, and manual vulnerability validation. Experience developing security automation tools, testing scripts, code-review frameworks, APIs, or security-related software components. Proficiency in at least one programming or scripting language, such as Python, JavaScript, Java, Go, C/C++, Bash, or PowerShell. Familiarity with security standards and resources such as OWASP, CVE, CVSS, CWE, and threat-intelligence databases. Strong analytical, problem-solving, technical-writing, and research-documentation skills.