Назад
Company hidden
3 дня назад

Application Security Engineer - Senior (Information Security)

Формат работы
remote (Global)
Тип работы
fulltime
Грейд
senior
Английский
b2
Релокация
Serbia/Spain/Cyprus +1 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer - Senior (Information Security): Designing and maintaining application security controls across the software development lifecycle with an accent on secure coding, threat modeling, and automated security testing. Focus on integrating SAST, DAST, IAST, RASP, and SCA tools into CI/CD pipelines, driving shift-left security, and improving developer security awareness.

Location: Worldwide; remote work available. Relocation is supported to Kazakhstan, Cyprus, Serbia, or Spain with full visa and work permit support for the employee and family.

Company

hirify.global is a fintech product company building technology products and protecting its systems, applications, and data through an Information Security function.

What you will do

  • Collaborate with development and operations teams, guide secure coding practices, participate in code reviews, and embed security throughout the SDLC.
  • Review application architectures, develop threat models, and identify security risks proactively.
  • Deploy and manage SAST, DAST, IAST, RASP, and SCA tools in CI/CD pipelines to automate detection and remediation.
  • Handle application security incidents and drive fast remediation through continuous testing.
  • Deliver workshops and improve developer awareness of OWASP, ASVS, and secure design standards.

Requirements

  • Professional experience with web or mobile programming languages.
  • Strong understanding of web architectures, including microservices.
  • Deep knowledge of OWASP Top 10, threat modeling, and security testing frameworks.
  • Hands-on familiarity with ZAP, Dependency-Track, and Burp.
  • Strong analytical skills and precise attention to detail.

Nice to have

  • Security certifications such as OSCP, OSWE, GWAPT, or GCPN.
  • Bug bounty or ethical-hacking program experience.
  • Experience with SaaS or cloud-native environments.
  • Familiarity with Kubernetes or container security.

Culture & Benefits

  • Creative, collaborative environment focused on innovative solutions.
  • Flexible work from company offices or remotely.
  • Healthcare coverage.
  • Education budget for language lessons, professional training, and certifications.
  • Wellness budget for mental health and fitness reimbursements.
  • 20 days of annual leave and paid sick leave.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →