9 дней назад
Senior Application Security Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Application Security Analyst (AppSec/AI): Improving application security products by analyzing vulnerabilities, reviewing secure code, and enhancing SAST, DAST, SCA, and KICS engines with an accent on accurate detection and secure coding practices. Focus on conducting security research, scripting in Python, leveraging AI for automation, and collaborating with Product Management and R&D.
Location: Braga, Portugal; hybrid work
Company
provides enterprise application security products and services through the cloud-native One platform, supporting security from code to cloud.
What you will do
- Analyze vulnerabilities and how they occur in open-source and proprietary code.
- Review secure code and improve the accuracy of application security analysis engines.
- Work with SAST, DAST, SCA, KICS, and related security products.
- Develop scripts and use AI to automate internal processes and support new product features.
- Conduct security research and track application security trends.
- Collaborate with Security Research, Product Management, R&D, and other teams.
Requirements
- 3–4 years of experience as an analyst or researcher, including secure code review.
- 3–4 years of experience in a similar security role.
- Strong understanding of application security concepts, vulnerabilities, secure coding practices, and the OWASP Top 10.
- Experience with Python scripting or programming and familiarity with interpreted and compiled languages.
- Basic experience in security research, bug bounties, and penetration testing.
- Excellent written and spoken English is required. Strong analytical, organizational, communication, and presentation skills are also expected.
Nice to have
- Degree or certification in a relevant field.
Culture & Benefits
- Professional development opportunities and challenging career work.
- Competitive compensation and benefits throughout the year.
- Work-life balance and a supportive work environment.
- Opportunities to work on application security products used by enterprise customers.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →