Application Security Engineer / Penetration Tester (iGaming)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Application Security Engineer / Penetration Tester (iGaming): Securing web applications, microservices, and REST and GraphQL APIs through vulnerability triage, secure code review, and hands-on penetration testing with an accent on OWASP risks, identity protocols, and authorization controls. Focus on identifying complex authorization bypasses, business logic flaws, and vulnerabilities across AWS and Kubernetes environments.
Location: Anywhere
Company
is a business advisory and services group focused on iGaming and entertainment, providing strategies and scalable solutions for market growth.
What you will do
- Triage, validate, prioritize, and track findings from SAST, SCA, and secret-scanning tools through remediation.
- Conduct manual and tool-assisted code reviews to identify vulnerabilities, logic flaws, and insecure implementation choices.
- Perform penetration testing of web applications, microservices, and APIs.
- Audit REST and GraphQL APIs, focusing on authentication, authorization, and business logic.
- Collaborate with engineering, product, and DevOps teams to balance risk mitigation with development workflows.
Requirements
- At least 3 years of experience in Application Security, Product Security, or Penetration Testing.
- Hands-on experience with Semgrep or OpenGrep, Gitleaks, Trivy, and OSV-Scanner.
- Experience with Burp Suite Pro, Nuclei, Subfinder, SQLmap, Metasploit, and NetExec.
- Strong knowledge of OWASP Top 10, OWASP API Security Top 10, OAuth 2.0, OIDC, JWT, SAML, RBAC, and ABAC.
- Ability to analyze modern application code and identify authorization bypasses, session management flaws, and business logic vulnerabilities.
- Intermediate English proficiency required. Basic AWS cloud security and Kubernetes security knowledge is also required.
Culture & Benefits
- Global medical coverage and health and wellness support.
- Professional growth opportunities and benefits programs.
- Compensation for gym, dental, psychological, and related services.
- Performance-driven rewards.
- Dynamic work environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →