Назад
Company hidden
2 месяца назад

Junior Application Security Specialist (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
Azerbaijan
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Junior Application Security Specialist (Cybersecurity): Identifying and remediating security vulnerabilities across products and infrastructure with an accent on vulnerability triage, code reviews, and threat modeling. Focus on assessing bug bounty reports, operating SAST/DAST tools, and documenting remediation guidance for engineering teams.

Location: On-site in Baku, Azerbaijan

Company

hirify.global is a high-scale payment platform providing specialized services for the gaming industry.

What you will do

  • Triage security findings from bug bounty reports and scanners, calculating severity and escalating appropriately.
  • Perform vulnerability assessments of web applications and APIs to identify and document risks.
  • Create precise security documentation and reproduction steps to help engineering teams remediate issues.
  • Participate in threat modeling sessions to identify trust boundaries, data flows, and attack surfaces.
  • Operate and monitor SAST, DAST, and dependency scanning tooling to reduce noise and track findings.
  • Conduct security-focused code reviews for PHP, Python, and Go codebases under senior guidance.

Requirements

  • Solid understanding of OWASP Top 10 (XSS, SQLi, CSRF, IDOR) and their root causes.
  • Strong knowledge of HTTP/S, REST APIs, CORS, and browser security policies.
  • Hands-on experience using Burp Suite to intercept, modify, and replay requests.
  • Ability to read and follow logic in at least one language: PHP, Python, JavaScript, or Go.
  • Strong analytical thinking and the ability to communicate technical findings clearly in writing.
  • Must be based in Baku for on-site work.

Nice to have

  • Active participation in CTF competitions or bug bounty programs.
  • Basic scripting skills for automation using Python or Bash.
  • Familiarity with CI/CD pipelines and cloud environments (GCP, AWS, or Azure).
  • Relevant entry-level certifications such as eWPT or CEH.

Culture & Benefits

  • Strong learning environment with direct support and mentorship from experienced security specialists.
  • Exposure to real-world security challenges within a large-scale payment infrastructure.
  • Culture that values directness, intellectual honesty, and thorough follow-through.
  • Opportunity to work in a global team spanning multiple time zones.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →