Назад
Company hidden
3 дня назад

Senior Application Security Engineer

Формат работы
remote (только United_kingdom)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (Application Security): Securing the applications powering Tripadvisor Experiences with an accent on encryption, secure APIs, identity management, threat modeling, and cloud security. Focus on designing scalable security controls, integrating SAST and DAST into development pipelines, investigating breaches, and mentoring engineers across teams.

Location: Based in London, UK; remote-friendly collaboration with on-site attendance as required by the team

Company

hirify.global connects travelers with experiences, accommodations, restaurants, and other travel services through content, technology, and two-sided marketplaces.

What you will do

  • Design and implement application security measures covering encryption, secure APIs, identity management, and secure software design.
  • Conduct threat modeling, risk assessments, manual security assessments, and code reviews.
  • Investigate security breaches, perform root cause analysis, and define corrective actions for vulnerabilities.
  • Develop and enforce scalable application security policies across engineering teams.
  • Advise engineering and product teams on security architecture and integrate security requirements into software development lifecycles.
  • Mentor junior engineers and advocate for security priorities and technical debt reduction.

Requirements

  • 4+ years of experience as a Security Engineer or Application Security Analyst.
  • Extensive experience with secure coding, threat modeling, vulnerability assessments, and incident response.
  • Hands-on experience with SAST and DAST tools and their integration into development pipelines.
  • Strong knowledge of encryption, identity management, API security, cloud security, and microservices architectures.
  • Leadership, mentoring, communication, and cross-functional collaboration skills.

Nice to have

  • Experience with GDPR, PCI-DSS, SOC 2, or similar regulatory frameworks.
  • Security certifications such as OSCP, OSCE, or equivalent.
  • Familiarity with current security tools and frameworks.

Culture & Benefits

  • Flexible remote-friendly collaboration with the option to work on-site as often as preferred or required by the team.
  • Flexible scheduling designed to support work-life balance.
  • Competitive compensation with base salary and annual bonuses.
  • Health benefits, employee assistance programs, tuition assistance, lifestyle benefits, and travel perks.
  • Donation matching and a referral rewards program.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →