Overview
Senior Security Engineer Jobs in Giza, Al Jizah, Egypt at 3i-Vision
Title: Senior Security Engineer
Company: 3i-Vision
Location: Giza, Al Jizah, Egypt
The Role:
We are looking for an offensive-minded Security Engineer to join our QC team. Unlike a traditional QC tester, you will think like an attacker. Your mission is to validate our security controls by attempting to bypass them. You will act as an internal Red Team, specifically targeting our data protection mechanisms, Windows drivers, web APIs, and desktop services to find gaps before real adversaries do.
Key Responsibilities:
- Red Teaming & Bypass Attempts: Actively attempt to bypass DLP policies, DRM restrictions, dynamic watermarks, and data classification rules on both web and desktop endpoints.
- Windows Driver & Kernel Validation: Identify vulnerabilities in our Windows agent, including IOCTL handling, memory corruption, privilege escalation vectors, and improper error handling in kernel mode.
- Web Application Security: Test for OWASP Top 10 vulnerabilities (e.g., IDOR, SSRF, broken access control) within the data discovery and classification dashboard.
- Endpoint Security Testing: Validate the integrity of the Windows agent’s process hooking, file system minifilter (if applicable), and anti-tampering protections.
- Security Gap Analysis: Document discovered attack paths, misconfigurations, and logic flaws. Recommend mitigations and work with developers to harden the product.
- Tool Development: Write scripts (.NET, Python, PowerShell, C/C++) to automate bypass techniques and fuzz testing for the driver and APIs.
- Collaboration: Work closely with developers to reproduce findings, validate patches, and shift-left security into the SDLC.
Required Qualifications:
Experience: 3+ years in application security, red teaming, or security-focused QA.
Windows Internals: Strong understanding of Windows kernel (drivers), memory management, process/threads, and WinAPI hooking.
Reverse Engineering: Ability to use tools like IDA Pro, Ghidra, WinDbg, or x64dbg to analyze binaries and drivers.
Offensive Skills: Experience bypassing DLP/DRM/watermarking solutions (e.g., screen scraping, VM detection bypass, clipboard manipulation, network exfiltration).
Web Security: Deep knowledge of JWT handling, CORS, GraphQL/REST API attacks, and session management.
Programming: Proficiency in C/C++ (for driver interaction) and .NET/Python or PowerShell (for exploit scripts).
Tools: Familiarity with Burp Suite, Process Monitor, API Monitor, and fuzzing frameworks (e.g., Defensics, Peach, or custom fuzzers).
Nice to Have:
- Published CVEs or public research on data protection bypass techniques.
- Knowledge of forensic anti-analysis techniques (TLS fingerprinting, VM evasion).
- Understanding of file system minifilters and network filter d