Назад
Company hidden
2 часа назад

Application Security Engineer (Cybersecurity)

Формат работы
remote (только Europe)/hybrid
Тип работы
fulltime
Грейд
middle/senior
Английский
c1
Страна
Serbia/Turkey/Italy +2 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Application Security Engineer (Cybersecurity): Perform threat modeling, security architecture reviews, and vulnerability testing for web applications and APIs with an accent on SBOM management and secure SDLC integration. Focus on designing security pipelines (SAST/DAST), collaborating on vulnerability remediation, and providing OWASP-aligned trainings.

Location: Remote in Bulgaria, Germany, Italy, Serbia, or Turkey. Hybrid work in locations with offices (2 days in-office, 3 days remote). Flexible schedule between 09:00/10:00 and 18:00/19:00 CET or EET.

Company

All-in-one platform for education and research leveraging machine intelligence and data science to tackle access inequality, tech clutter, and student engagement.

What you will do

  • Perform threat modeling, security architecture reviews, and design analysis for web apps and APIs.
  • Conduct manual and automated security testing in development and pre-release stages.
  • Design and implement security pipelines including SAST and DAST, integrated into SDLC.
  • Manage SBOM generation and consumption across the SDLC.
  • Collaborate with devs for timely vulnerability remediation.
  • Maintain OWASP-aligned security guidance and deliver team trainings.
  • Track evolving appsec threats, tools, and industry trends.

Requirements

  • 3–5 years in application security, focused on web apps and API security.
  • Good knowledge of one scripting/programming language (Python, JavaScript, C#, Go).
  • Experience with OWASP ZAP, Burp Suite, Snyk or similar tools.
  • Familiarity with secure coding, DevSecOps, container security.
  • Strong understanding of CVE, CVSS, vulnerability disclosure.
  • Excellent command of business English; send resume in English only.

Nice to have

  • Knowledge of SBOM standards (CycloneDX, SPDX) and CI/CD integration.
  • Software composition analysis (SCA) tools experience.

Culture & Benefits

  • Choice of work equipment (laptop, monitor, etc.).
  • English classes (iTalki – $130 monthly).
  • Flexible schedule CET/EET.
  • Newborn bonus (€500 per child).
  • Patent remuneration.
  • Paid leave.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →