Application Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Application Security Engineer (Cybersecurity): Perform threat modeling, security architecture reviews, and vulnerability testing for web applications and APIs with an accent on SBOM management and secure SDLC integration. Focus on designing security pipelines (SAST/DAST), collaborating on vulnerability remediation, and providing OWASP-aligned trainings.
Location: Remote in Bulgaria, Germany, Italy, Serbia, or Turkey. Hybrid work in locations with offices (2 days in-office, 3 days remote). Flexible schedule between 09:00/10:00 and 18:00/19:00 CET or EET.
Company
All-in-one platform for education and research leveraging machine intelligence and data science to tackle access inequality, tech clutter, and student engagement.
What you will do
- Perform threat modeling, security architecture reviews, and design analysis for web apps and APIs.
- Conduct manual and automated security testing in development and pre-release stages.
- Design and implement security pipelines including SAST and DAST, integrated into SDLC.
- Manage SBOM generation and consumption across the SDLC.
- Collaborate with devs for timely vulnerability remediation.
- Maintain OWASP-aligned security guidance and deliver team trainings.
- Track evolving appsec threats, tools, and industry trends.
Requirements
- 3–5 years in application security, focused on web apps and API security.
- Good knowledge of one scripting/programming language (Python, JavaScript, C#, Go).
- Experience with OWASP ZAP, Burp Suite, Snyk or similar tools.
- Familiarity with secure coding, DevSecOps, container security.
- Strong understanding of CVE, CVSS, vulnerability disclosure.
- Excellent command of business English; send resume in English only.
Nice to have
- Knowledge of SBOM standards (CycloneDX, SPDX) and CI/CD integration.
- Software composition analysis (SCA) tools experience.
Culture & Benefits
- Choice of work equipment (laptop, monitor, etc.).
- English classes (iTalki – $130 monthly).
- Flexible schedule CET/EET.
- Newborn bonus (€500 per child).
- Patent remuneration.
- Paid leave.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →