Application Security Engineer - Senior
Brak informacji o wynagrodzeniu
SeniorFull-time
#411189·Dodano wczoraj·0
Źródło: SOFTSWISSTech Stack / Keywords
SecuritySoftware DevelopmentSDLCOWASPArchitectureNetwork
Firma i stanowisko
SOFTSWISS is hiring for their Application Security team to ensure secure software deployment and robust application security throughout the software development lifecycle (SDLC).
Wymagania
- 5+ years of experience in Application Security.
- Knowledge of secure development processes and best practices.
- Deep understanding of web application security mechanisms including SOP, CORS, CSP.
- Deep understanding of common vulnerabilities (OWASP Top 10) and prevention methods.
- Knowledge of secure system/application architecture and design principles.
- Understanding of modern threats to high-performance web applications.
- Understanding of modern authentication/authorization patterns (OAuth, OIDC, JWT).
- Practical expertise in vulnerability identification through security assessments and secure code review.
- Ability to perform root-cause analysis to drive systemic fixes.
- University degree in Computer Science, Information Security, or related field, or equivalent experience.
- English and Russian proficiency at upper-intermediate level (B2+).
Nice to have:
- Passion for programming.
- Technical knowledge of network and operating systems security.
- Hands-on DevSecOps experience.
- Experience with bug bounty programs and/or CTFs.
- Deep knowledge of SAST/DAST tools and customization.
- Relevant certifications such as OSWE, GWEB.
Obowiązki
- Partner with product teams during the design phase to lead threat modeling and risk assessment sessions, translating security threats into actionable requirements.
- Perform in-depth manual code reviews on critical applications to identify logical vulnerabilities as part of white-box assessments.
- Plan, design, implement, automate, and support AppSec tools.
- Contribute to developing company-wide secure code development and deployment processes.
- Triage security vulnerabilities with clear descriptions ensuring mitigation.
- Manage the bug bounty program and collaborate with researchers and internal teams on vulnerability resolution.
- Partner with Dev/QA teams throughout development to provide consulting, knowledge sharing, and actionable security guidance.
Benefity
- Private health insurance.
- Sports benefits.
- Comprehensive Mental Health Program.
- Free English lessons (online).
- Local language courses.
- Paid time off.
- Maternity leave support.
- Referral program rewards.
- Upskilling, internal workshops, participation in professional conferences and corporate events.
Opieka zdrowotna
Karta sportowa
Kursy językowe
Płatny urlop
SOFTSWISS
18 aktywnych ofert