Search for new things / novelty Tenacity Need for reflection Need for autonomy Involvement at work Ambition Improvisation
ABA Technology is a sovereign industrial ecosystem that designs and offers a wide range of services and products covering engineering, electronics, hardware equipment, Edge AI, IoT, as well as defense and security fields.
Our structure is organized around three complementary poles:
ABA Sovereignty which develops the future technologies of hardware, Edge AI, and critical systems, enabling states, industries, and institutions to maintain control over their data, infrastructures, and technological sovereignty.
ABA Fusion IA which designs artificial intelligence solutions based on strict principles of ethics, transparency, and responsibility. Thanks to energy-efficient, distributed, and auditable architectures, this pole develops sustainable AI, respectful of the environment and human dignity.
ABA Life which deploys an integrated One Health approach, transforming technology into sustainable impact for the benefit of people, territories, and ecosystems. This pole relies on an integrated platform architecture, structured around five complementary entities.
At ABA Technology, we design sovereign and responsible artificial intelligence to heal, strengthen, and protect.
We believe that technology must protect what matters most. That intelligence must serve humans, never replace them.
From health to education, from territories to the planet, our AI is designed for the real world: ethical, resilient, and deeply human.
Aba Technology is a company driven by innovation, where creativity, experimentation, and bold thinking shape everyday work. This entrepreneurial mindset is supported by strong structure and process discipline, ensuring efficiency and consistent quality. Teams thrive in a collaborative and caring environment that values trust, support, and close teamwork. While performance and competition play a lighter role, the focus remains on agility, collective alignment, and impactful innovation.
Penetration Testing (Pentest):
• Plan and conduct application penetration tests (web, REST/GraphQL API, mobile) in black, gray, and white box.
• Perform configuration audits and targeted security code reviews.
• Exploit vulnerabilities in a controlled manner to demonstrate their real impact (proof of concept).
• Cover OWASP Top 10, OWASP ASVS, OWASP API Security Top 10, and OWASP Testing Guide repositories.
• Write clear and prioritized audit reports (management summary + technical detail), with remediation recommendations.
• Perform re-audits to verify vulnerability remediation.
• Participate in bug bounty programs and manage external reports if applicable.
Compliance and Governance:
• Manage and maintain compliance with repositories: ISO 27001/27002, GDPR (and Moroccan Law 09-08 on personal data protection).
• Conduct risk analyses (EBIOS RM, ISO 27005) on projects and applications.
• Write and maintain security policies, standards, and procedures (PSSI, charters, secure development standards).
• Prepare and support internal and external certification audits.
• Monitor action and remediation plans with the relevant teams.
• Integrate security into projects from the design phase (Security by Design, architecture reviews).
Awareness and Continuous Improvement:
• Train and raise developers' awareness of application security (secure coding, workshops, internal CTFs).
• Maintain active monitoring of vulnerabilities (CVEs, exploits, advisories) and regulatory changes.
• Contribute to the response to security incidents (analysis, containment, lessons learned).
Hard Skills:
• Education: Master's degree (Bac+5) in cybersecurity, computer science, or equivalent.
• Experience: Minimum 3 years in penetration testing and/or security auditing, with exposure to compliance topics.
• Valued Certifications: OSCP, eWPT/eWPTX, BSCP (Burp Suite Certified Practitioner), CEH, ISO 27001 Lead Implementer/Auditor, CISA.
• Web/API Pentest: Proficiency in Burp Suite Pro, OWASP ZAP, Nmap, Nuclei, sqlmap, Metasploit, ffuf/dirsearch.
• Application Vulnerabilities: Injections (SQLi, XSS, SSTI, SSRF), IDOR/BOLA, authentication and session flaws, deserialization, CSRF, misconfigurations.
• Development: Code reading (JavaScript/Node.js, Python), exploitation scripting (Python, Bash).
• Protocols and Web: HTTP/S, TLS, OAuth2/OIDC, JWT, SAML, WebSockets.
• Compliance: ISO 27001, GDPR/Law 09-08, PCI-DSS; EBIOS RM / ISO 27005 methodologies.
• GRC Tools: Proficiency in a risk/compliance management tool is a plus.
Soft Skills:
• Impeccable ethics and strict adherence to the legal framework of tests.
• Curiosity and offensive creativity ("attacker mindset").
• Excellent writing skills (reports for technical and non-technical audiences).
• Pedagogical approach, diplomacy, and ability to engage with business units and management.
Search for new things / novelty Tenacity Need for reflection Need for autonomy Involvement at work Ambition Improvisation
Here you can find a recommendation rate for this vacancy, as well as information on how to promote your application. Log in / Register to view this personalised information.
ReKrute offers you this new personality test to help you get to know yourself better and make the most of your applications. Take it now, it only takes 5 minutes maximum.