Qualifications
• Bachelor’s degree in Computer Science, Information Security, or a related field. Advanced degrees or equivalent professional experience are preferred.
• 4+ years of experience in offensive security testing, with a strong focus on privacy vulnerabilities.
• Proven experience in penetration testing, red teaming, and vulnerability assessments, particularly in privacy contexts.
• Relevant security certifications such as OSCP, OSEP, OSWA, OSWE, OWSE, OSED, GPEN, GXPN, GWAPT, GMOB, BSCP etc.
• Hands on technical experience in web, mobile and infrastructure penetration testing with tools like Burp Suite Pro, SQLMap, Frida, Objection, Android Studio, XCode, MobSF, Drozer
• Experience with conducting reverse engineering on mobile applications, including applications with anti-emulator and obfuscation protections
• Familiarity and experience working with frameworks like MITRE ATT&CK/D3FEND, NIST, CCPA, COPPA, OECS, ISO etc.
• Proven hands-on experience with programming and scripting languages (e.g., C/C++, C#, Python, Golang, JS).
Preferred Qualifications:
• Experience with automation, big data and relational databases.
• Contributions to the privacy or security community through research, publications, or participation in bug bounty programs.
• Relevant industry certifications (e.g., CIPP, CIPT, CIPM)