16 часов назад
AppSec - Vulnerability Management Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
AppSec - Vulnerability Management Engineer (Cybersecurity): Strengthening application security across web and mobile platforms through security testing, code review, vulnerability remediation, and developer guidance with an accent on OWASP Top 10 vulnerabilities, custom security tooling, and bug bounty operations. Focus on validating fixes, conducting root cause analysis, developing Semgrep and Nuclei rules, and driving feasible technical remediation.
Location: Istanbul / Maslak, Turkey; hybrid workplace
Company
builds commerce and financial technology products, including payment infrastructure, digital wallets, smart credit systems, and personalized financial services.
What you will do
- Provide application security expertise and secure coding guidance to engineering teams.
- Perform web and mobile application security testing and identify vulnerabilities, including OWASP Top 10 issues.
- Validate vulnerability fixes through manual code review of relevant commits.
- Document vulnerabilities, perform root cause analysis, and recommend feasible remediation solutions.
- Develop custom security tools and security rules using technologies such as Semgrep and Nuclei.
- Manage the bug bounty platform and promote security best practices among developers.
Requirements
- Experience with vulnerability management and enterprise remediation efforts.
- Experience with multiple programming or scripting languages, such as Java, Golang, and Python.
- Familiarity with frontend and backend web application frameworks, including Spring, Gin, and React.
- English proficiency sufficient for reading technical documentation and collaborating with international developers.
- Strong communication skills and the ability to work collaboratively in an Agile environment.
- Ability to work in a hybrid setup in Istanbul / Maslak.
Nice to have
- Professional certifications such as eWPT, eWPTXv2, OSWE, eMAPT, or GWAPT.
- Community contributions, including public CVEs, bug bounty recognition, or technical blogs.
Culture & Benefits
- Flexible hybrid working model with work-from-abroad opportunities and a summer working model.
- Customizable FlexBenefits budget covering meals, health insurance, fuel support, or shopping credits.
- Extended wellbeing support, including health screenings, in-house doctors, psychologist and dietitian services, and HPV vaccination coverage.
- Annual training and conference allowance, LMS access, and in-person learning sessions.
- International collaboration with colleagues across offices in Berlin, Amsterdam, Dubai, and other locations.
- Team rituals, events, social activities, mentoring, and opportunities for hands-on professional growth.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →