
Security Engineer (Pentesting, Incident Response & Investigations)
Talkdeskhá mais de um mês
- Tempo inteiro
- Intermédio
Descrição
Join Talkdesk as a Security Engineer specializing in Pentesting, Incident Response, and Security Investigations. You will play a key role in detecting, investigating, and preventing security incidents while proactively identifying weaknesses across our platforms and applications. This role involves performing manual and automated penetration testing of web applications, APIs, cloud-based systems, and AI/ML models, conducting security assessments focusing on emerging threats like prompt injection and adversarial attacks, and leading incident response efforts including detection, containment, and eradication.
Your responsibilities will include analyzing logs and forensic artifacts to support investigations, triaging and validating findings from penetration tests, working with engineering teams to explain vulnerabilities and verify fixes, performing threat modeling using methodologies like STRIDE, and continuously researching emerging threats and attack techniques. You will act as a security subject-matter expert during incidents and high-risk technical discussions, helping improve Talkdesk's overall security posture through proactive testing and lessons learned. This position requires strong application and systems security knowledge, practical penetration testing experience, understanding of OWASP Top 10 and AI exploitation patterns, and excellent communication skills.
Competências
- Application Security
- Systems Security
- Web Technologies
- Penetration Testing
- OWASP Top 10
- AI Security
- Prompt Injection Detection
- Security Investigations
- Incident Response
- Log Analysis
- Forensic Analysis
- Threat Hunting
- Cryptography
- Linux/Unix
- Python
- Security Event Analysis
- STRIDE Threat Modeling
- Cloud Security
- AWS
- API Security
- Mobile Application Security
- DAST
- SAST
- IAST
- Git
- Ruby
- Kotlin
- RabbitMQ
- Redis
- MongoDB
- PostgreSQL
Responsabilidades
- Perform manual and automated penetration testing of web applications, APIs, cloud-based systems, and AI/ML models
- Conduct security assessments of AI-driven features, focusing on risks like prompt injection, data leakage, and adversarial attacks
- Conduct security investigations to identify root causes, attack paths, and impact of security incidents
- Lead or actively participate in incident response, including detection, containment, eradication, and post-incident reviews
- Analyze logs, telemetry, and forensic artifacts to support investigations and threat hunting activities
- Triage, validate, and prioritize findings from internal and external penetration tests
- Work closely with engineering teams to explain vulnerabilities, recommend pragmatic remediations, and verify fixes
- Support the development and improvement of incident response playbooks and processes
- Perform threat modeling (e.g., STRIDE) to identify realistic attack scenarios
- Continuously research emerging threats, attack techniques, and exploitation methods relevant to the environment
- Act as a security subject-matter expert (SME) during incidents and high-risk technical discussions
- Help improve Talkdesk's overall security posture through lessons learned and proactive testing
Benefícios
- Inclusive and diverse workplace culture
- Community involvement and volunteer opportunities
- Global team with autonomy to drive meaningful impact
- Agile and collaborative work environment
- Peer review culture
- Continuous learning opportunities
Empregos semelhantes
