Назад
Company hidden
обновлено 5 дней назад

Application Security Engineer

70 - 90GBP
Формат работы
remote (только Europe)
Тип работы
fulltime
Грейд
middle/senior
Английский
b2
Страна
UK/Spain/Italy
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (Web and Cloud Security): Designing secure application architectures and protecting cloud-based web and mobile applications with an accent on threat modeling, penetration testing, and automated security controls. Focus on integrating SAST, DAST, SCA, and WAF protections, investigating security alerts, and supporting 24x7 monitoring.

Location: Full remote; candidates must be located in Italy, Spain, or the UK. The role includes on-call shifts for 24x7 security monitoring and support.

Salary: £70–£90 per year.

Company

hirify.global uses data and technology to provide online motor insurance, serving drivers in Italy, the UK, and Spain.

What you will do

  • Define security requirements and design application architectures using a secure-by-default approach.
  • Conduct threat modeling, code reviews, and penetration testing for cloud-based web and mobile applications.
  • Implement, manage, and automate SAST, DAST, SCA, and WAF security controls.
  • Partner with Product teams to strengthen application protection and promote secure development practices.
  • Investigate, manage, and resolve security alerts while contributing to Security Engineering initiatives.

Requirements

  • Strong knowledge of web and mobile security vulnerabilities, AI security risks, OWASP Top 10, and CWE.
  • Practical experience with threat modeling frameworks such as STRIDE, code reviews, penetration testing, and SAST, DAST, and SCA tools.
  • Proficiency in scripting or programming, such as Python or Rust, plus experience with CI/CD and Infrastructure as Code tools such as Pulumi.
  • Availability for on-call shifts supporting 24x7 security monitoring.
  • Strong English communication skills and experience working in Agile environments.

Nice to have

  • Experience with secure AWS design and implementation and Kubernetes or EKS security.
  • Experience configuring WAFs such as Cloudflare and working with EDR, SIEM, or SOAR platforms.
  • Security certifications such as OSCP, OSWA/E, BSCP, PWPA/E, or eWPT.
  • Participation in security research, bug bounty programs, or CTF competitions.

Culture & Benefits

  • Flexible remote work with the option to work from home, the office, or a combination of both.
  • Learning resources, mentorship, and an individual growth plan.
  • Private healthcare, gym discounts, wellbeing programs, and mental health support.
  • Collaboration with more than 350 engineers across software development, infrastructure, operations, and security.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →