Назад
6 дней назад

Application Security Engineer (Cybersecurity)

120 000 - 140 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Страна
Austria
vacancy_detail.hirify_telegram_tooltipВакансия из Telegram канала -

Мэтч & Сопровод

Покажет вашу совместимость и напишет письмо

Описание вакансии

TL;DR
Application Security Engineer (Cybersecurity): Owning application and product security from design through deployment with an accent on secure development workflows, automated testing, vulnerability management, and software supply-chain security. Focus on integrating SAST, DAST, and SCA into CI/CD pipelines, conducting threat modeling and penetration testing, and building security capabilities from scratch.

Application Security Engineer

Company

Transak

Conditions

3 days agoSalary: 120K - 140K

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will own application and product security from design through deployment. You will integrate security into development workflows, review code and architecture, automate security testing, manage software supply-chain risks, oversee vulnerability remediation, perform penetration testing, develop secure coding standards, run security training and bug bounty activities, and provide evidence for regulatory and compliance requirements.

Requirements

  • 5+ years of security engineering experience focused on application or product security
  • Deep knowledge of web and API security including OWASP Top 10 authentication authorisation and session management
  • Hands-on experience with Burp Suite OWASP ZAP Snyk or Aikido
  • Strong programming skills in JavaScript Node.js or Python
  • Experience integrating security tools into GitLab CI Jenkins or GitHub Actions
  • Practical software composition analysis and SBOM experience
  • Experience owning vulnerability management programmes
  • Experience applying threat modelling to business flows and distributed systems
  • Understanding of cryptography secrets management and identity and access management
  • Excellent communication skills for engineering audiences
  • Ability to build a security capability from scratch
  • Cryptocurrency blockchain fintech payments or custody security experience is advantageous
  • Knowledge of SBOM formats build provenance SLSA EPSS and CISA KEV is advantageous
  • Knowledge of DORA MiCA SOC 2 ISO 27001 or GDPR is advantageous
  • Experience managing penetration testing vendors or bug bounty programmes is advantageous
  • OSCP OSWE GWAPT or CSSLP certification is advantageous

Responsibilities

  • Embed security into the software development lifecycle
  • Conduct code reviews threat modeling and architecture reviews
  • Implement and tune SAST DAST and SCA solutions
  • Automate application security testing in CI/CD pipelines
  • Manage SBOMs dependencies provenance standards and approved base images
  • Maintain the vulnerability register and drive remediation
  • Perform penetration testing and vulnerability assessments
  • Manage external penetration testing engagements
  • Develop secure coding standards and reusable security components
  • Deliver role-based security training
  • Create a security champions programme
  • Run the bug bounty programme
  • Research application and supply-chain threats
  • Evidence controls for DORA MiCA SOC 2 and ISO 27001

Benefits

  • Equity options
  • Comprehensive benefits offering

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →

Текст вакансии взят без изменений

Источник -