Platform Security Engineer

F5 F5 · Enterprise · Bangalore, India

This role focuses on internal red-team penetration testing of F5's BIG-IP product lines, performing code and configuration security reviews, participating in threat modeling, identifying and exploiting security vulnerabilities, and building custom tools to assist security assessments. The position involves consulting with development teams on findings and remediation, and presenting findings to ensure products align with security standards.

What you'd actually do

  1. Hands-on penetration testing of F5 products
  2. Perform code and configuration security reviews in critical parts of the products
  3. Participating in threat modelling of new product features
  4. Manual identification and exploitation of security vulnerabilities.
  5. Detailed analysis of issues identified, including proof of concept, reproduction steps, and recommended remediation.

Skills

Required

  • Pen-Testing
  • security assessment
  • reading code in C, C++, JAVA
  • assessment of containerized environments (docker, k8, Rest API)
  • manual and automatic testing tools
  • security principles, theories, and attacks
  • Linux OS mechanisms, networking, and protocols
  • pen testing of Web based, Linux based
  • developing tools in Python

Nice to have

  • Golang
  • node.js
  • static code analysis
  • fuzzing tools
  • traffic processing products assessment (Router, Load Balancer, DNS, FW, WAF)
  • Bachelor’s degree in Computer Science or a closely related field with 7+ years of experience
  • common pen test tools (Kali Linux, Metasploit, Burp Suite, Wireshark, Qualys, NMAP, Nessus)
  • Industry certifications (CEH, OSCP, OSCE, OSWE, GPEN, GCIH, GWAPT, or GXPN)
  • Secure SDLC
  • DevSecOps
  • Security standards (OWASP, CWE, NIST, OSSTMM)

What the JD emphasized

  • At least 5 years of expertise in hands-on Pen-Testing and security assessment.
  • Strong experience with assessment of containerized environments (docker, k8, Rest API) is a must.
  • Experience with traffic processing products assessment (Router, Load Balancer, DNS, FW, WAF)