Назад
Company hidden
2 месяца назад

Junior Application Security Specialist (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
Azerbaijan
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Junior Application Security Specialist (Cybersecurity): Identifying, assessing, and remediating security vulnerabilities across products and infrastructure with an accent on code reviews, vulnerability triage, and threat modeling. Focus on monitoring SAST/DAST tools, assessing bug bounty reports, and documenting reproduction steps for engineering teams.

Location: On-site in Baku

Company

hirify.global is a large-scale payment platform providing specialized financial technology for the gaming industry.

What you will do

  • Triage security findings from bug bounty reports and automated scanners, calculating severity and escalating issues.
  • Perform security assessments of web applications and APIs to identify and document risks.
  • Create precise security documentation, including reproduction steps and remediation guidance.
  • Participate in threat modeling sessions to identify trust boundaries and attack surfaces.
  • Operate and monitor SAST, DAST, and dependency scanning tooling to reduce noise and track findings.
  • Review code in PHP, Python, and Go to identify common vulnerability classes.

Requirements

  • Solid understanding of OWASP Top 10 and web security fundamentals (CSRF, XSS, IDOR, SQLi).
  • Deep knowledge of HTTP request/response cycles, REST APIs, and browser security (SOP, Cookies, CORS).
  • Hands-on experience with Burp Suite or similar web application security testing tools.
  • Ability to read and follow logic in at least one language: PHP, Python, JavaScript, or Go.
  • Strong analytical thinking and clear written communication skills.
  • Must be based in Baku for on-site work.

Nice to have

  • Active participation in bug bounty programs or CTF competitions.
  • Basic scripting abilities in Python or Bash for automation.
  • Familiarity with CI/CD pipelines and cloud environments (GCP, AWS, or Azure).
  • Entry-level credentials or certifications such as eWPT, CEH, or PortSwigger Web Security Academy.

Culture & Benefits

  • Strong learning environment with direct support and mentorship from experienced security specialists.
  • Exposure to real-world security challenges within a high-scale production environment.
  • A corporate culture that values directness, intellectual honesty, and thorough follow-through.
  • Collaboration within a global team operating across multiple time zones.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →