Назад
21 день назад

Security Engineer (Web Application Security)

Формат работы
remote (Global)
Тип работы
fulltime
Грейд
middle
Английский
b2
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer (Web Application Security): Protecting a global gaming platform by managing vulnerabilities, conducting threat modeling, responding to incidents, and strengthening security infrastructure with an accent on web application security, Bug Bounty assessment, and secure development practices. Focus on reproducing and remediating vulnerabilities, evaluating attack vectors, configuring WAF and SIEM-related defenses, and guiding engineering teams through secure architecture decisions.

Location: 100% remote; work from anywhere

Company

A global gaming and technology company operating a platform for playing, learning, and enjoying chess.

What you will do

  • Lead the vulnerability management program, including triaging, reproducing, assessing, prioritizing, and remediating findings from Bug Bounty programs.
  • Conduct threat modeling with engineering teams to identify attack vectors and align proposed designs with security standards.
  • Manage incident response by reviewing penetration testing results and SIEM reports, creating remediation tasks, and tracking them to completion.
  • Maintain and optimize security infrastructure, including Web Application Firewall configurations and other security systems.
  • Evaluate and implement security tools, from requirements gathering and vendor assessment through procurement and deployment.
  • Advise development teams on secure architecture, software development lifecycle practices, security awareness, and documentation.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related technical field, or equivalent professional experience.
  • At least 3 years of professional experience in web application security.
  • Hands-on expertise with Burp Suite or equivalent web request analysis and tampering tools.
  • Strong written English communication skills for explaining technical security concepts to diverse audiences.
  • Experience working effectively in fully distributed or remote teams.
  • Ability to collaborate cross-functionally with engineering and development teams.

Nice to have

  • Hands-on experience managing or participating in Bug Bounty programs.
  • Programming experience with PHP or JavaScript.
  • Experience with penetration testing methodologies, SIEM platforms, security monitoring systems, or WAF management.
  • Understanding of secure software development lifecycle practices and experience with Jira or similar tools.
  • Strong ownership, accountability, and commitment to continuous learning.

Culture & Benefits

  • 100% remote work from anywhere.
  • Work in a fully distributed organization spanning more than 60 countries.
  • Collaborate in a flat, mission-driven, non-corporate environment.
  • Contribute to a global chess platform serving more than 250 million players.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →