Назад
Company hidden
3 часа назад

Application Security Engineer / Penetration Tester (iGaming)

Формат работы
remote (Global)
Тип работы
fulltime
Грейд
middle
Английский
b1
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Application Security Engineer / Penetration Tester (iGaming): Securing web applications, microservices, and REST and GraphQL APIs through vulnerability triage, secure code review, and hands-on penetration testing with an accent on OWASP risks, identity protocols, and authorization controls. Focus on identifying complex authorization bypasses, business logic flaws, and vulnerabilities across AWS and Kubernetes environments.

Location: Anywhere

Company

hirify.global is a business advisory and services group focused on iGaming and entertainment, providing strategies and scalable solutions for market growth.

What you will do

  • Triage, validate, prioritize, and track findings from SAST, SCA, and secret-scanning tools through remediation.
  • Conduct manual and tool-assisted code reviews to identify vulnerabilities, logic flaws, and insecure implementation choices.
  • Perform penetration testing of web applications, microservices, and APIs.
  • Audit REST and GraphQL APIs, focusing on authentication, authorization, and business logic.
  • Collaborate with engineering, product, and DevOps teams to balance risk mitigation with development workflows.

Requirements

  • At least 3 years of experience in Application Security, Product Security, or Penetration Testing.
  • Hands-on experience with Semgrep or OpenGrep, Gitleaks, Trivy, and OSV-Scanner.
  • Experience with Burp Suite Pro, Nuclei, Subfinder, SQLmap, Metasploit, and NetExec.
  • Strong knowledge of OWASP Top 10, OWASP API Security Top 10, OAuth 2.0, OIDC, JWT, SAML, RBAC, and ABAC.
  • Ability to analyze modern application code and identify authorization bypasses, session management flaws, and business logic vulnerabilities.
  • Intermediate English proficiency required. Basic AWS cloud security and Kubernetes security knowledge is also required.

Culture & Benefits

  • Global medical coverage and health and wellness support.
  • Professional growth opportunities and benefits programs.
  • Compensation for gym, dental, psychological, and related services.
  • Performance-driven rewards.
  • Dynamic work environment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →