Şirkət Haqqında
Şirkət: SOCAR Tech
SOCAR Tech — SOCAR və onun ekosistemi üçün texnologiya, rəqəmsallaşma və innovasiya sahəsində kompleks həllər təqdim edən texnologiya şirkətidir. Şirkət rəqəmsal transformasiya, ERP və korporativ həllər, Data və Süni İntellekt, kibertəhlükəsizlik, OT və sənaye texnologiyaları istiqamətlərində fəaliyyət göstərərək, strategiya və həllərin hazırlanmasından onların tətbiqi və davamlı dəstəyinə qədər tam xidmət spektri təqdim edir. SOCAR Tech-in əsas məqsədi müasir texnologiyalar və innovativ yanaşmalar vasitəsilə biznes proseslərinin səmərəliliyini artırmaq, rəqəmsal transformasiyanı sürətləndirmək və SOCAR Qrupu, eləcə də digər təşkilatlar üçün uzunmüddətli dəyər yaratmaqdır. SOCAR Tech brendinə keçiddən əvvəl şirkət Caspian Innovation Center (CIC) adı altında fəaliyyət göstərib. Bu dövrdə formalaşmış peşəkar komanda, texnoloji ekspertiza və həyata keçirilmiş layihələr SOCAR Tech-in bugünkü inkişafının möhkəm təməlini təşkil edir. Yeni brend kimliyi ilə SOCAR Tech bu təcrübəni daha böyük ambisiyalarla davam etdirərək, Azərbaycanda və beynəlxalq bazarlarda texnologiya və rəqəmsal transformasiya sahəsində imkanlarını genişləndirməyi hədəfləyir.
SOCAR Tech şirkətinin bütün vakansiyaları
Vakansiya Təsviri
Responsibilities: Planning and conducting penetration tests of internal and external infrastructure (network, Active Directory, Windows/Linux servers); Security assessment of web applications (OWASP Top 10, business logic vulnerabilities, authentication/authorization flaws); Analysis of attack paths in Active Directory environments (Kerberoasting, ACL abuse, delegation vulnerabilities, lateral movement scenarios); Assessing identified vulnerabilities based on their risk level and preparing technical and management-level reports; Collaborating with infrastructure and application teams during the remediation process and conducting retesting of fixes; Working closely with the SOC team to test and improve detection rules; Participating in phishing simulations and social engineering assessments; Security assessment of AI-based systems and LLM-integrated applications (prompt injection, jailbreak, data leakage, and test scenarios based on the OWASP Top 10 for LLM Applications); Effective use of AI-based tools in penetration testing processes (reconnaissance, payload generation, and report preparation automation); Managing the vulnerability management process: administration of Rapid7 and Tenable Nessus scanners, configuration of scan profiles, analysis of results, and false-positive filtering; Analyzing the impact of new CVEs on the infrastructure and prioritizing them; Defining the scope, planning, and leading the execution of penetration testing projects; Mentoring team specialists, providing technical guidance, and ensuring the quality of prepared reports; Developing and improving penetration testing methodologies, internal standards, and procedures; Presenting test results to management and explaining risks in business terms. Requirements: At least 3 years of practical experience in information security, including at least 1 year of practical experience in penetration testing; Practical certification requirement: OSCP or an equivalent certification — CRTO, GPEN, or similar. OSEP, OSWE, and CRTE certifications are considered an advantage; Ability to independently plan and conduct network and infrastructure penetration tests and lead projects at the project level; Practical experience in security assessment of Active Directory environments and a deep understanding of key attack paths; Ability to manually test web applications, going beyond automated scan results to identify business logic, authentication, and authorization vulnerabilities; Practical experience with vulnerability scanners: configuration of scans, triage, and validation of results using Tenable Nessus, Rapid7 InsightVM/Nexpose, or equivalent solutions; Knowledge of post-exploitation, privilege escalation, and analysis of key security configurations in Windows and Linux systems; Manual testing of API security, REST and GraphQL APIs, including Broken Object Level Authorization (BOLA/IDOR), mass assignment, and rate limiting bypass; Cloud security knowledge, including basic penetration testing scenarios in AWS / Azure / GCP environments (IAM misconfiguration, S3 bucket exposure, metadata service abuse); Understanding of security in containerized/microservices environments, including key Docker and Kubernetes misconfiguration points and container escape scenarios; Automation of AI-oriented tasks in daily penetration testing activities; Proficiency in at least one scripting language for test process automation and, when required, development of simple tools: Python, PowerShell, or Bash; Ability to document findings in a clear, reproducible, and risk-based reporting format and provide specific remediation recommendations; Experience in technical leadership or mentoring within a team and ability to independently manage complex projects; Fluency in Azerbaijani; Proficiency in English for working with technical documentation and reports. Preferred Qualifications: Additional certifications: OSEP, OSWE, CRTP/CRTE, BSCP, or equivalent practical certifications; Understanding of EDR detection and evasion techniques; Understanding of how attacks are reflected from a logging and detection perspective; Experience with C2 frameworks: Cobalt Strike, Sliver, Havoc, or equivalent tools; Participation in CTFs, HackTheBox/TryHackMe profiles, bug bounty experience, or personal security research, such as blog posts, CVEs, open-source tools, etc.; Interest or practical experience in AI/LLM security: OWASP LLM Top 10, MITRE ATLAS, AI red teaming; Familiarity with AI-assisted penetration testing tools: PentestGPT, Burp AI, and equivalent solutions We Offer: Meal allowance; Annual performance bonuses; Corporate health program: Voluntary insurance and special discounts for gyms; Access to Digital Learning Platforms. Note: Only candidates who meet the requirements of the vacancy will be contacted for the next stage. Interested candidates can send their CV to the e-mail address in the Apply for job button.