328 lines
8.6 KiB
YAML
328 lines
8.6 KiB
YAML
# Apex Tier-1 API Scan Adapters
|
|
# Targets: Red Team, Penetration Testing, OT/ICS Pentest, AI Security, Adversary Emulation
|
|
# Strategy: zero-token direct JSON API hits
|
|
|
|
title_filter:
|
|
positive:
|
|
- "Red Team"
|
|
- "Penetration Test"
|
|
- "Pen Test"
|
|
- "Pentest"
|
|
- "Offensive Security"
|
|
- "Adversary Emulation"
|
|
- "Adversary Simulation"
|
|
- "Purple Team"
|
|
- "AI Security"
|
|
- "AI Red Team"
|
|
- "LLM Security"
|
|
- "AI/ML Security"
|
|
- "ML Security"
|
|
- "GenAI Security"
|
|
- "AI Adversarial"
|
|
- "Prompt Security"
|
|
- "OT Security"
|
|
- "OT Penetration"
|
|
- "ICS Security"
|
|
- "ICS Penetration"
|
|
- "SCADA"
|
|
- "Industrial Control"
|
|
- "Critical Infrastructure"
|
|
- "OT/ICS"
|
|
- "OT Pentest"
|
|
- "Cloud Security"
|
|
- "Cloud Penetration"
|
|
- "AWS Security"
|
|
- "Security Engineer"
|
|
- "Security Consultant"
|
|
- "Security Researcher"
|
|
- "Vulnerability Research"
|
|
- "Exploit Development"
|
|
- "Threat Emulation"
|
|
- "Threat Hunter"
|
|
- "Application Security"
|
|
- "Product Security"
|
|
- "AppSec"
|
|
- "Principal Security"
|
|
- "Staff Security"
|
|
- "Ethical Hacker"
|
|
|
|
negative:
|
|
- "SOC Analyst I"
|
|
- "SOC Analyst Tier 1"
|
|
- "Tier 1"
|
|
- "T1 Analyst"
|
|
- "GRC"
|
|
- "Compliance Analyst"
|
|
- "Auditor"
|
|
- "Privacy Analyst"
|
|
- "Risk Analyst"
|
|
- "Governance"
|
|
- "Sales"
|
|
- "Account Executive"
|
|
- "BDR"
|
|
- "SDR"
|
|
- "Marketing"
|
|
- "Recruiter"
|
|
- "Customer Success"
|
|
- "Renewals"
|
|
- "Intern"
|
|
- "Internship"
|
|
- "Co-op"
|
|
- "Apprentice"
|
|
- "Junior"
|
|
- "Entry Level"
|
|
- "Entry-Level"
|
|
- "Graduate Program"
|
|
- ".NET Developer"
|
|
- "Java Developer"
|
|
- "iOS Developer"
|
|
- "Android Developer"
|
|
- "PHP Developer"
|
|
- "Ruby Developer"
|
|
- "COBOL"
|
|
- "Mainframe"
|
|
- "SAP "
|
|
- "Salesforce Admin"
|
|
- "Web3"
|
|
- "Blockchain"
|
|
- "Crypto"
|
|
|
|
seniority_boost:
|
|
- "Senior"
|
|
- "Staff"
|
|
- "Principal"
|
|
- "Lead"
|
|
- "Associate Principal"
|
|
- "Head"
|
|
- "Director"
|
|
|
|
tracked_companies:
|
|
# === OT / ICS Security ===
|
|
- name: Dragos
|
|
careers_url: https://job-boards.greenhouse.io/dragos
|
|
api: https://boards-api.greenhouse.io/v1/boards/dragos/jobs
|
|
enabled: true
|
|
notes: "OT/ICS security market leader — dream company"
|
|
|
|
- name: Nozomi Networks
|
|
careers_url: https://job-boards.greenhouse.io/nozominetworks
|
|
api: https://boards-api.greenhouse.io/v1/boards/nozominetworks/jobs
|
|
enabled: true
|
|
notes: "OT/IoT visibility & security"
|
|
|
|
- name: Shift5
|
|
careers_url: https://job-boards.greenhouse.io/shift5
|
|
api: https://boards-api.greenhouse.io/v1/boards/shift5/jobs
|
|
enabled: true
|
|
notes: "OT security for transportation/defense"
|
|
|
|
# === Pure-Play Red Team / Offensive ===
|
|
- name: SpecterOps
|
|
careers_url: https://job-boards.greenhouse.io/specterops
|
|
api: https://boards-api.greenhouse.io/v1/boards/specterops/jobs
|
|
enabled: true
|
|
notes: "BloodHound creators, elite adversary emulation"
|
|
|
|
- name: Bishop Fox
|
|
careers_url: https://job-boards.greenhouse.io/bishopfox
|
|
api: https://boards-api.greenhouse.io/v1/boards/bishopfox/jobs
|
|
enabled: true
|
|
|
|
- name: Praetorian
|
|
careers_url: https://job-boards.greenhouse.io/praetorian
|
|
api: https://boards-api.greenhouse.io/v1/boards/praetorian/jobs
|
|
enabled: true
|
|
notes: "Offensive security + managed services"
|
|
|
|
# === Major Cyber Vendors ===
|
|
- name: Rapid7
|
|
careers_url: https://careers.rapid7.com/
|
|
enabled: false
|
|
notes: "Metasploit stewards, consulting services. Uses Clinch (PageUp) ATS — no public API adapter yet."
|
|
|
|
- name: Arctic Wolf
|
|
careers_url: https://arcticwolf.wd1.myworkdayjobs.com/External
|
|
enabled: true
|
|
workday:
|
|
host: https://arcticwolf.wd1.myworkdayjobs.com
|
|
tenant: arcticwolf
|
|
site: External
|
|
|
|
- name: Recorded Future
|
|
careers_url: https://job-boards.greenhouse.io/recordedfuture
|
|
api: https://boards-api.greenhouse.io/v1/boards/recordedfuture/jobs
|
|
enabled: true
|
|
|
|
- name: CrowdStrike
|
|
careers_url: https://crowdstrike.wd5.myworkdayjobs.com/crowdstrikecareers
|
|
enabled: true
|
|
workday:
|
|
host: https://crowdstrike.wd5.myworkdayjobs.com
|
|
tenant: crowdstrike
|
|
site: crowdstrikecareers
|
|
notes: "Dream company — Falcon, Services red team (Workday)"
|
|
|
|
- name: Sophos
|
|
careers_url: https://jobs.lever.co/sophos
|
|
enabled: true
|
|
notes: "Lever-hosted"
|
|
|
|
- name: Tenable
|
|
careers_url: https://www.tenable.com/careers
|
|
enabled: true
|
|
|
|
# === Crowdsourced / Bug Bounty ===
|
|
- name: HackerOne
|
|
careers_url: https://jobs.ashbyhq.com/hackerone
|
|
api: https://api.ashbyhq.com/posting-api/job-board/hackerone?includeCompensation=true
|
|
enabled: true
|
|
|
|
- name: Bugcrowd
|
|
careers_url: https://job-boards.greenhouse.io/bugcrowd
|
|
api: https://boards-api.greenhouse.io/v1/boards/bugcrowd/jobs
|
|
enabled: true
|
|
|
|
- name: Synack
|
|
careers_url: https://job-boards.greenhouse.io/synack
|
|
api: https://boards-api.greenhouse.io/v1/boards/synack/jobs
|
|
enabled: true
|
|
|
|
- name: Horizon3.ai
|
|
careers_url: https://jobs.ashbyhq.com/horizon3ai
|
|
enabled: true
|
|
notes: "Ashby-hosted"
|
|
|
|
# === Federal / Cleared Contractors ===
|
|
- name: Booz Allen Hamilton
|
|
careers_url: https://bah.wd1.myworkdayjobs.com/BAH_Jobs
|
|
enabled: true
|
|
workday:
|
|
host: https://bah.wd1.myworkdayjobs.com
|
|
tenant: bah
|
|
site: BAH_Jobs
|
|
notes: "SECRET clearance asset (Workday)"
|
|
|
|
- name: Leidos
|
|
careers_url: https://leidos.wd5.myworkdayjobs.com/External
|
|
enabled: true
|
|
workday:
|
|
host: https://leidos.wd5.myworkdayjobs.com
|
|
tenant: leidos
|
|
site: External
|
|
notes: "SECRET clearance asset (Workday)"
|
|
|
|
- name: Two Six Technologies
|
|
careers_url: https://job-boards.greenhouse.io/twosixtechnologies
|
|
api: https://boards-api.greenhouse.io/v1/boards/twosixtechnologies/jobs
|
|
enabled: true
|
|
|
|
# === AI Labs ===
|
|
- name: Anthropic
|
|
careers_url: https://job-boards.greenhouse.io/anthropic
|
|
api: https://boards-api.greenhouse.io/v1/boards/anthropic/jobs
|
|
enabled: true
|
|
|
|
- name: OpenAI
|
|
careers_url: https://jobs.ashbyhq.com/openai
|
|
enabled: true
|
|
notes: "Ashby-hosted job board (653 live postings)"
|
|
|
|
- name: HiddenLayer
|
|
careers_url: https://job-boards.greenhouse.io/hiddenlayer
|
|
api: https://boards-api.greenhouse.io/v1/boards/hiddenlayer/jobs
|
|
enabled: true
|
|
|
|
aggregators:
|
|
# Remotive — remote-first jobs, free public API, search-by-keyword
|
|
- name: Remotive — Red Team
|
|
type: remotive
|
|
query: "red team"
|
|
limit: 50
|
|
enabled: true
|
|
|
|
- name: Remotive — Penetration Tester
|
|
type: remotive
|
|
query: "penetration tester"
|
|
limit: 50
|
|
enabled: true
|
|
|
|
- name: Remotive — AI Security
|
|
type: remotive
|
|
query: "AI security"
|
|
limit: 50
|
|
enabled: true
|
|
|
|
- name: Remotive — Offensive Security
|
|
type: remotive
|
|
query: "offensive security"
|
|
limit: 50
|
|
enabled: true
|
|
|
|
# RemoteOK — remote tech, free JSON API, tag-based
|
|
- name: RemoteOK — Security
|
|
type: remoteok
|
|
tag: security
|
|
enabled: true
|
|
|
|
# USAJobs — federal roles, free JSON API, requires registered API key.
|
|
# Creds live in Infisical (apex folder): USAJOBS_API_KEY, USAJOBS_USER_AGENT.
|
|
# Pull with: eval $(~/.local/bin/creds env apex) before running scan.
|
|
# NOTE: USAJobs keyword search uses substring AND matching. Keep queries
|
|
# single-keyword and let the global title_filter downselect.
|
|
- name: USAJobs — penetration
|
|
type: usajobs
|
|
query: "penetration"
|
|
limit: 100
|
|
enabled: true
|
|
|
|
- name: USAJobs — red team
|
|
type: usajobs
|
|
query: "red team"
|
|
limit: 100
|
|
enabled: true
|
|
|
|
- name: USAJobs — offensive security
|
|
type: usajobs
|
|
query: "offensive security"
|
|
limit: 100
|
|
enabled: true
|
|
|
|
- name: USAJobs — vulnerability
|
|
type: usajobs
|
|
query: "vulnerability"
|
|
limit: 100
|
|
enabled: true
|
|
|
|
- name: USAJobs — adversary
|
|
type: usajobs
|
|
query: "adversary"
|
|
limit: 100
|
|
enabled: true
|
|
|
|
- name: USAJobs — SCADA / ICS
|
|
type: usajobs
|
|
query: "SCADA"
|
|
limit: 100
|
|
enabled: true
|
|
|
|
- name: USAJobs — industrial control
|
|
type: usajobs
|
|
query: "industrial control"
|
|
limit: 100
|
|
enabled: true
|
|
|
|
- name: USAJobs — exploit research
|
|
type: usajobs
|
|
query: "exploit"
|
|
limit: 100
|
|
enabled: true
|
|
|
|
# Generic RSS — use this for company career pages that publish an RSS feed
|
|
# but no JSON API. Only 20 most recent items per poll is common.
|
|
- name: Deloitte — RSS (US External Careers)
|
|
type: rss
|
|
url: https://apply.deloitte.com/en_US/careers/Home/feed/
|
|
company: Deloitte
|
|
enabled: true
|
|
notes: "Dream company. Custom Taleo-like ATS, generic RSS feed (20 most recent jobs)."
|