Web Application Security Engineer (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Web Application Security Engineer (AI): Ensuring the security of AI-enabled financial applications with an accent on threat modeling, DevSecOps enforcement, and vulnerability management. Focus on conducting penetration testing, implementing security automation, and guiding development teams in secure coding practices.
Location: Hybrid (Tunis, Tunisia)
Company
is a global leader in cloud-based spend management solutions, leveraging AI to simplify accounts payable processes for thousands of organizations worldwide.
What you will do
- Review product features for security by design and perform threat modeling.
- Execute SAST and DAST scanning and conduct penetration testing.
- Enforce DevSecOps practices and provide secure development guidance to engineering teams.
- Assess and implement security tools to enhance application security maturity.
- Document security assessments, test results, and remediation plans for stakeholders.
- Report on the security posture of web applications, including vulnerability metrics and risk assessments.
Requirements
- Engineering degree in Computer Science or equivalent professional experience.
- Minimum of 5 years of experience in application security, secure coding, or penetration testing.
- Strong understanding of web application vulnerabilities and remediation (OWASP Top 10, LLM, API).
- Proven experience in conducting security assessments and vulnerability management.
- Ability to work effectively in a hybrid environment based in Tunis.
Nice to have
- Experience implementing application security frameworks like SAMM and BSIMM.
- Proficiency in multiple programming languages such as C# or Python.
- Deep understanding of web services and network protocols.
Culture & Benefits
- Collaborative and meritocratic work culture with supportive leadership.
- Opportunities for career growth and professional development.
- Commitment to fair and equitable compensation practices.
- Global community focused on innovation and problem-solving.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →