Назад
Company hidden
2 дня назад

AppSec Analyst

Формат работы
remote (только Europe)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Spain, Latvia, Montenegro
Релокация
Spain, Latvia, Montenegro
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

AppSec Analyst: Conducts comprehensive security assessments and hands-on penetration testing of applications, APIs, and microservices with an accent on identifying and remediating vulnerabilities throughout the SDLC. Focus on analyzing scan results, triaging findings, creating detailed reports, and ensuring secure coding practices.

Location: Remote or on-site from one of our offices in Riga, Budva, or Barcelona.

Company

hirify.global is a company with a dynamic, international team passionate about excellence in product development within the gambling/gaming and fintech industries.

What you will do

  • Conduct manual web application, API, and microservice security testing.
  • Perform regular security assessments of new features and changes pre-deployment.
  • Analyze and validate security findings from automated SAST, DAST, and SCA tools.
  • Triage, validate, and prioritize vulnerabilities, creating detailed reports with remediation guidance.
  • Collaborate with product teams to define security requirements and review technical designs.
  • Configure and optimize security scanning tools integrated into CI/CD pipelines.

Requirements

  • Minimum of 2-3 years of experience in application security testing or penetration testing.
  • Proficiency in English at an intermediate level or higher.
  • Strong practical experience in web application penetration testing and security assessments (OWASP Top 10, API security).
  • Hands-on experience with security testing tools such as Burp Suite, OWASP ZAP, Nuclei.
  • Solid understanding of common vulnerabilities in modern web applications and APIs (REST, GraphQL, WebSockets).
  • Experience analyzing SAST, DAST, and SCA scan results and triaging findings.

Nice to have

  • Professional security certifications such as OSCP, OSWE, CEH, eWPT, or GWAPT.
  • Experience with container and Kubernetes security testing.
  • Familiarity with cloud security (AWS, GCP) and cloud-native application testing.
  • Experience in the gambling/gaming or fintech industry with understanding of regulatory requirements.

Culture & Benefits

  • Comprehensive Health Insurance and 100% Paid Sick Leave.
  • Continuous Learning & Growth opportunities and tailored language courses.
  • Generous Paid Time Off (20 vacation days, plus 6 additional days off).
  • Diverse & Dynamic international team and exciting corporate events.
  • Top-Quality Equipment and a Welfare Program.
  • Celebration of life's milestones with thoughtful gifts.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →

Текст вакансии взят без изменений

Источник - загрузка...