обновлено 2 месяца назад
Senior Application Security Engineer (Software Supply Chain)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Application Security Engineer (Software Supply Chain): Securing a multi-tenant SaaS platform and its software supply-chain control plane with an accent on application security, cloud-native systems, threat modeling, and artifact integrity. Focus on reviewing APIs and distributed architectures, building security automation, investigating vulnerabilities, and improving secure engineering practices across an embedded engineering tribe.
Location: Must be based in Ireland or the United Kingdom; regular travel may be required for team meetings, planning, customer work, and events. Belfast headquarters is used for working sessions, planning, all-hands, and team events.
Company
operates a fully managed, multi-tenant SaaS platform for securing, governing, and distributing software artifacts across more than 30 ecosystems and formats.
What you will do
- Embed within an engineering tribe and participate in planning, design reviews, code reviews, incident learning, and delivery discussions.
- Threat-model product and platform changes across APIs, workers, data stores, queues, object storage, identity, policy, and tenant boundaries.
- Review production code and architecture for authentication, authorization, data access, secrets handling, artifact integrity, signing, auditability, and abuse cases.
- Build security tooling, paved roads, libraries, checks, and automation for engineering teams.
- Operate security controls including SAST, DAST, SCA, secrets scanning, container scanning, IaC scanning, dependency analysis, and runtime signals.
- Investigate and remediate vulnerabilities, support security incidents and red/blue exercises, and contribute to SOC 2, ISO 27001, and EU CRA control work.
Requirements
- Approximately 5+ years of hands-on application security experience, or equivalent software engineering and security experience.
- Strong software engineering skills with a focus on Python; familiarity with TypeScript, Go, or Rust is advantageous.
- Deep knowledge of web and API security, including OWASP Top 10, business logic flaws, authentication and authorization, token handling, REST, GraphQL, and multi-tenant access control.
- Practical threat-modeling and vulnerability research experience across applications, APIs, cloud-native systems, and distributed services.
- Strong AWS and cloud-native security experience, including IAM, KMS, S3, containers, Terraform, CI/CD, secrets handling, logging, and tenant isolation.
- Must be based in Ireland or the United Kingdom and have the right to work independently without requiring sponsorship.
Nice to have
- Experience securing artifact, package, or container registries, CI/CD systems, DevOps platforms, developer tooling, or software supply-chain products.
- Experience with sandboxing, workload isolation, policy engines, OPA/Rego, eBPF, or secure runtime environments.
- Contributions to open-source security or software supply-chain projects.
- Familiarity with Datadog, AWS Security Hub, Okta, GitHub Advanced Security, Snyk, Semgrep, Trivy, or Wiz.
- Security certifications such as OSCP, CSSLP, GPEN, GWAPT, GCSA, or CISSP.
Culture & Benefits
- Engineering-first, builder-oriented security culture with high standards, practical thinking, and strong ownership.
- Flexible working policies and a remote-first collaboration environment supported by Slack, Google Docs, and Linear.
- Comprehensive health, dental, and vision insurance.
- Generous annual leave and flexible, family-friendly wellbeing policies.
- Professional development budget for equipment, training, books, conferences, travel, and certifications.
- Belfast office facilities for working sessions, planning, meetups, and team activities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Senior Product Security Engineer
90 000 - 100 000GBP
3 дня назад
Secure Software Engineer (Application Security)
100 000 - 150 000$
5 дней назад
Application Security Engineer - Senior (Information Security)
4 дня назад
Application Security Engineer (AI)
WRITER
4 дня назад
Staff Security Engineer Application Security (AI)
183 000 - 240 000$
10 дней назад
Product Security Engineer (AI)
175 000 - 200 000$