Himalayas Remote / WFH Teknologi & IT Full Time

Application Security Engineer - Senior

SOFTSWISS

Poland, Serbia Gaji dirahasiakan Diposting 17 jam lalu
Lokasi Poland, Serbia
Gaji Gaji dirahasiakan
Tipe Kerja Full Time · Remote
Negara Polandia

Deskripsi Pekerjaan

Informasi lengkap tentang posisi dan persyaratan

Ringkasan Yukerja

Lowongan Application Security Engineer - Senior di SOFTSWISS kami kurasi dari Himalayas (kategori Teknologi & IT). Posisi ini ditandai sebagai remote — pastikan timezone dan syarat lokasi kandidat di deskripsi resmi. Yukerja.com bukan pemberi kerja — lamaran diproses di situs sumber resmi.

Overview:

We are expanding our Application Security team and need someone who is not only experienced but also shares our commitment to excellence.

Purpose of the role:

Our goal is to make sure that we deploy secure software to production without unnecessary bottlenecks, that applications are properly hardened, and security vulnerabilities, once discovered, are fixed by the developers.

As a Senior Application Security Engineer, you will play a crucial role in ensuring the security of our applications throughout the entire software development lifecycle (SDLC). You will partner closely with the product teams to identify, analyze, and mitigate security vulnerabilities, contributing to the creation of trustworthy and robust products.

Key responsibilities:

  • Partner with product teams during the design phase to lead threat modeling and risk assessments sessions, translating complex security threats into clear, actionable security requirements.

  • Perform in-depth manual code reviews on critical applications to identify complex logical vulnerabilities as part of white-box security assessment.

  • Plan, design, implement, automate and (if you wish) support AppSec tools.

  • Contribute to building a company-wide processes for secure code development and deployment.

  • Triage identified security vulnerabilities, provide clear and actionable descriptions and ensure these findings are properly addressed and mitigated.

  • Manage the bug bounty program, collaborate with researches and internal teams to resolve the discovered vulnerabilities.

  • Partner with Dev/QA teams throughout the development lifecycle to enhance the application's security posture by providing expert consulting, continuous knowledge sharing, and actionable security guidance.

Required Experience:

  • 5+ years of experience in Application Security.

  • Knowledge of secure development processes and best practices.

  • Deep understanding of web application security mechanisms (i.e., how the web actually works? What is SOP and why do we need CORS? What is CSP?).

  • Deep understanding of common web application vulnerabilities (i.e., OWASP Top 10), and the most effective ways to prevent them.

  • Knowledge of secure system/application architecture and design principles.

  • Understanding of modern threats to high-performance web applications that are used by millions of users daily.

  • Understanding of modern authentication/authorisation patterns (OAuth, OIDC, JWT, etc.)

  • Practical hands-on expertise in identifying vulnerabilities through security assessment and secure code review, coupled with the ability to perform deep root-cause analysis to drive systemic fixes.

  • University degree in Computer Science, Information Security, or related field, or equivalent combination of education and experience.

  • English and Russian proficiency at an upper-intermediate level (B2+).

Nice to have:

  • Passion about programming.

  • Technical knowledge of network and operating systems security.

  • Hands-on DevSecOps experience.

  • Practice of participation in bug bounty programs and/or CTFs.

  • Deep knowledge of SAST/DAST tools, including customisation.

  • Relevant certifications (i.e., OSWE, GWEB, etc.).

Our Benefits:

  • Private health insurance

  • Sports benefits

  • Comprehensive Mental Health Program

  • Free English lessons (online)

  • Local language courses

  • Paid time off

  • Maternity leave support

  • Referral program rewards

  • Upskilling, internal workshops, and participation in professional conferences and corporate events

Originally posted on Himalayas

Disclaimer: Yukerja.com adalah agregator lowongan kerja, bukan pemberi kerja. Lowongan ini diagregasi dari Himalayas. Proses lamaran dilakukan di situs resmi perusahaan atau portal sumber. Kami tidak bertanggung jawab atas keakuratan informasi lowongan.

Tips Melamar Application Security Engineer - Senior

  1. Baca deskripsi lengkap dan pastikan skill Anda match sebelum melamar ke SOFTSWISS.
  2. Sesuaikan CV dan cover letter dengan kata kunci dari job description — terutama untuk kategori Teknologi & IT.
  3. Klik Lamar Sekarang untuk diarahkan ke Himalayas. Proses rekrutmen sepenuhnya di situs sumber.
  4. Siapkan portfolio atau LinkedIn yang update jika diminta di tahap screening.
  5. Waspadai permintaan transfer uang — lowongan resmi tidak memungut biaya.

Artikel terkait: CV ATS · Blog Karir & Tips