6 дней назад
Application Security Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Application Security Analyst (Web Application Security/OWASP): Performing application security assessments across the software development lifecycle with an accent on threat modeling, web application penetration testing, and manual and automated security testing. Focus on identifying and mitigating vulnerabilities, collaborating with development and DevOps teams, and integrating security into product planning and delivery.
Location: Hybrid work
Company
develops data, AI, and intelligent software solutions in partnership with leading companies across more than 25 countries.
What you will do
- Perform application security analysis and threat modeling for new and existing products and projects.
- Analyze requirements and collaborate with analysts, architects, designers, developers, DevOps teams, and other stakeholders.
- Conduct web application penetration testing and manual and automated security testing.
- Identify and help mitigate application security risks throughout the software development lifecycle.
- Contribute to product and feature development from planning through delivery.
Requirements
- Knowledge of HTTP, programming languages, and the OWASP Top 10 vulnerabilities, including how to identify, exploit, and fix them.
- Experience with Burp Suite or other web security scanners such as ZAP, Acunetix, or Netsparker.
- Working knowledge of Linux or Windows operating systems.
- English at least at the level required to read technical documentation.
- Ability to collaborate across multidisciplinary teams, communicate clearly, and work independently when needed.
- Interest in developing further in application security.
Nice to have
- Scripting and automation experience with PowerShell, Python, or Bash.
- Knowledge of OWASP ASVS, the OWASP Testing Guide, and product or feature planning.
- Understanding of browser security mechanisms such as SOP, cookies, CSP, and HSTS.
- Experience with OAuth, JWT, WebSockets, public clouds, and CI/CD pipeline orchestrators.
- Additional penetration testing experience.
Culture & Benefits
- Hybrid work with flexibility and balance.
- Opportunities to work on international projects.
- Different career paths and opportunities to explore other roles.
- Continuous learning and professional development.
- AI-driven environment using current technologies.
- Benefits and practical perks supporting day-to-day work.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 дней назад
Staff Security Engineer (AI)
56 - 77$
7 дней назад
Application Security Architect (AI)
158 050 - 193 325$
6 дней назад
Application Security Researcher (AI)
11 дней назад
Application Security Engineer (AI)
100 000 - 130 000$
7 дней назад
Senior Application Security Engineer (AI)
164 300 - 222 300$
Decagon
9 дней назад
Lead Application Security Engineer (AI)
170 000 - 305 000$