12 дней назад
Application Security Engineer (SAST/SCA)
1 750 000 - 2 000 000HUF
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Application Security Engineer (SAST/SCA): Securing the application code, dependencies, APIs, and software development lifecycle behind Canvas, Mastery, and Parchment products with an accent on risk reduction, vulnerability management, and developer enablement. Focus on threat modeling, secure code review, CI/CD security automation, and translating technical risk into actionable product decisions.
Location: Budapest, Hungary; hybrid
Salary: HUF 1,750,000–2,000,000 per month
Company
Develops education and personal development products, including Canvas, Mastery, and , used by students, instructors, and educational institutions.
What you will do
- Own application security across code, dependencies, APIs, and the software development lifecycle.
- Classify security risk, adjudicate severity, drive remediation, and hand off residual risk with documented reasoning.
- Design compensating controls, investigate false positives, and maintain application security tooling and data pipelines.
- Build CI/CD security gates, SAST/SCA coverage, secure defaults, and paved-road libraries.
- Perform threat modeling, secure code reviews, technical specification reviews, and developer enablement.
- Partner with engineering and product teams to communicate security risk in terms of business impact and support major incident escalations as a subject-matter expert.
Requirements
- Experience with application security across application code, dependencies, APIs, and the SDLC.
- Ability to assess exploitability, exposure, data sensitivity, blast radius, and business impact in context.
- Experience with vulnerability management, remediation, compensating controls, false-positive adjudication, threat modeling, and secure code review.
- Experience building or maintaining CI/CD security automation and SAST/SCA pipelines.
- Ability to collaborate with developers and product managers and explain technical risk to non-engineering audiences.
- Availability for a hybrid role based in Budapest, Hungary.
Nice to have
- Experience with Snyk, CodeQL, or Wiz Code.
- Experience supporting bug bounty researcher communication and triage.
- Experience with major security incident escalations.
Culture & Benefits
- Full-time employees participate in an ownership program.
- Generous time off, local holidays, and an annual late-December recharge period based on departmental needs.
- Wellness programs and mental health support.
- Professional development resources and tuition reimbursement.
- Inclusive culture with employee recognition programs and the tools needed for the role.
Hiring process
- Background check and identity verification are required for all employees.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →