TL;DR
Application Security Engineer (AWS): Designing and implementing application security controls for PHP and JavaScript web applications, integrating security into the CI/CD pipeline and performing security reviews. Focus on defining bot protection with AWS WAF, managing vulnerabilities, and responding to application-level security events.
Location: Remote (Europe); the team is based in Porto, Portugal.
Salary: €40,000–€70,000
Company
hirify.global is an HRTech product company operating a secure SaaS platform focused on employer reviews and insights.
What you will do
- Design, implement, and continuously improve application security controls for PHP and JavaScript web applications.
- Embed security into the CI/CD pipeline using GitHub and GitHub Actions.
- Perform secure code reviews, threat modeling, and architecture reviews for new and existing features.
- Define and operate Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and dependency-scanning tools.
- Monitor, analyze, and respond to application-level security events using Security Hub, GuardDuty, CloudTrail, and WAF logs.
- Lead vulnerability management for application and cloud services, including prioritization and remediation guidance.
Requirements
- Strong experience in application security, ideally for PHP-based web applications.
- Solid understanding of web security fundamentals (OWASP Top 10, authentication, authorization, session management, input validation).
- Hands-on experience with AWS security services, including Security Hub, GuardDuty, CloudTrail, AWS WAF & Shield.
- Experience securing containerized workloads on ECS (EC2 & Fargate), ALBs, and Lambdas.
- Proven experience with SAST, DAST, and dependency-scanning tools (e.g., Snyk, Dependabot, Trivy, OWASP ZAP, Burp).
- Fluent in English (Portuguese is a plus).
Culture & Benefits
- Up to 12 weeks Workation.
- Mobile devices also for private use.
- Remote work option.
- Trust-based working hours.
- Transparent, competitive salary.
- Bring your dog to the office.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →