Senior Application Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Application Security Engineer (Cybersecurity): Embed security into SDLC, conduct threat modeling, secure code reviews, and security testing for subscription commerce platform with an accent on secure-by-design practices, tooling integration, and vulnerability mitigation. Focus on running STRIDE sessions, automating checks in CI/CD pipelines, and enabling engineering teams through training and guidance.
Location: Czechia (Remote)
Company
Global leader in subscription commerce platform automating workflows for IT distributors, MSPs, and telcos.
What you will do
- Integrate security across all SDLC phases and partner with engineering teams on secure practices.
- Run threat modeling sessions using STRIDE to identify threats and ensure secure-by-design principles.
- Perform security-focused code and architecture reviews with actionable guidance.
- Conduct manual and automated web application security testing and operate AppSec tools like SAST, DAST, SCA.
- Integrate and automate security checks in CI/CD pipelines and recommend tooling improvements.
- Support incident response, triage vulnerabilities, and contribute to root cause analysis.
- Enable engineers via training, documentation, secure coding guidelines, and hands-on guidance.
Requirements
- Strong understanding of secure software development principles and common vulnerabilities (OWASP Top 10, CWE).
- Experience with modern SDLCs, agile workflows, and integrating security tools into CI/CD.
- Hands-on web application security testing and pragmatic risk assessment.
- Knowledge of cloud-native architectures, APIs, and microservices.
- Background collaborating closely with product and engineering teams.
Nice to have
- Exposure to security metrics, maturity models, or building AppSec programs.
Culture & Benefits
- Fully remote work with work-from-anywhere scheme for travel.
- Flexible working hours.
- Health and life insurance program.
- Learning & development budget.
- Tech-driven, friendly team with international mindset.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →