TL;DR
Senior Application Security Engineer (Cybersecurity): Collaborating with security researchers and internal teams to identify and remediate vulnerabilities, and improve development processes for secure SDLC adoption. Focus on performing threat modeling, vulnerability testing, and advising development teams on secure coding practices for enterprise systems.
Location: Serbia
Company
hirify.global is a global cyber protection company providing natively integrated cybersecurity, data protection, and endpoint management solutions for businesses and users.
What you will do
- Drive SSDLC adoption for custom application logic in enterprise systems.
- Validate and triage external security reports and bug bounty submissions.
- Perform threat modeling to identify attack paths and define mitigations.
- Advise development teams on secure coding practices and perform vulnerability testing.
- Conduct security assessments of internally developed software components.
- Lead post-mortem reviews of application security incidents and vulnerabilities, acting as an application security advisor and trainer.
Requirements
- 5+ years of experience in Application Security.
- Strong understanding of security models for Web/REST APIs, cloud, mobile, and desktop applications.
- Hands-on experience with security assessment tools and attack techniques, beyond simple input injection.
- Experience performing code assessments in Go, Python, Rust, C/C++, and JavaScript.
- Knowledge of Salesforce security features and controls.
- Strong communication skills in English.
Nice to have
- Published security research, open-source tools, blog posts, or active participation in bug bounty programs.
Culture & Benefits
- Work with a world leader in cyber protection, with 15 offices worldwide and over 1800 employees in 50+ countries.
- Corporate culture focused on making a positive impact, built on mutual trust, respect, and contribution.
- Opportunity to work in a dynamic, global environment with a "never give up" attitude.
- Equal opportunity employer committed to diversity and inclusion.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →