Application Security Engineer (AppSec)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Application Security Engineer (AppSec): Enhancing security posture by embedding security practices throughout the SDLC with an accent on vulnerability assessments and secure coding. Focus on implementing SAST/DAST pipelines, performing threat modeling, and remediating vulnerabilities across web and mobile applications.
Location: Hybrid (Location not specified)
Company
is an independent technology consulting firm providing guidance and solutions to businesses globally across multiple business lines.
What you will do
- Conduct application security assessments and identify vulnerabilities in web and mobile applications.
- Perform and coordinate security testing using SAST, DAST, and manual assessment methods.
- Collaborate with development teams to remediate vulnerabilities and implement secure coding practices.
- Participate in threat modeling and security design reviews throughout the project lifecycle.
- Review application architectures to provide security recommendations and best practices.
- Integrate security controls into CI/CD and SDLC processes and prepare detailed assessment reports.
Requirements
- Bachelor's degree in Engineering, Computer Science, Information Systems, or a related field.
- Minimum 6 years of experience in Application Security Testing.
- Strong understanding of OWASP Top 10 and secure software development practices.
- Hands-on experience with SAST, DAST, SCA, and penetration testing tools.
- English: B2 level proficiency required for technical documentation and communication.
Culture & Benefits
- Inclusive work environment committed to diversity and equal opportunity.
- Opportunity to work within an international team across 60 countries.
- Professional growth within a global technology consulting ecosystem.
Hiring process
- Brief virtual or phone introductory call to discuss motivations.
- Average of 3 interviews with the line manager and team members.
- Technical case study or assessment depending on the role requirements.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →