Application Security Engineer
Brak informacji o wynagrodzeniu
MidFull-time
#411199·Dodano wczoraj·0
Źródło: SOFTSWISSTech Stack / Keywords
SecuritySoftware DevelopmentSDLCTestingOWASPArchitectureCybersecurityNetwork
Firma i stanowisko
SOFTSWISS is a growing company hiring an Application Security Engineer to ensure secure software deployment and vulnerability mitigation throughout the software development lifecycle.
Wymagania
- 3+ years experience in application security, software development, or related technical roles.
- Solid understanding of web fundamentals including HTTP, HTTPS, cookie storage, and session management.
- Knowledge of web application security mechanisms such as SOP, CORS, CSP.
- Comprehensive understanding of common web vulnerabilities including OWASP Top 10 and mitigation strategies.
- Knowledge of secure system and application architecture principles.
- Hands-on expertise in manual security assessments and secure code reviews.
- Ability to clearly explain the business impact of threats and vulnerabilities to developers and product teams.
- Strong security-first mindset with continuous learning drive.
- University degree in Computer Science, Information Security or equivalent experience.
- Proficiency in English and Russian at upper-intermediate level (B2+).
Nice to have:
- Passion about programming.
- Technical knowledge of network and operating systems security.
- Hands-on DevSecOps experience.
- Participation in bug bounty programs and/or CTFs.
- Knowledge of SAST/DAST tools including customization.
- Relevant certifications such as BSCP, eWPT.
Obowiązki
- Partner with product teams during design phase for threat modeling and risk assessment.
- Perform in-depth manual code reviews on critical applications.
- Tune and adjust rulesets for automated security scanning tools.
- Develop scripts and automation tools to streamline workflows.
- Assist developers in understanding discovered security risks and threats.
- Triage vulnerabilities from bug bounty program and collaborate to resolve flaws.
- Collaborate continuously with Dev/QA teams providing security consulting and guidance.
- Develop and maintain internal security knowledge base including secure coding guidelines.
Benefity
- Full-time remote work opportunities and flexible working hours.
- Private insurance.
- Additional 1 day off per calendar year.
- Sports program compensation.
- Comprehensive mental health program.
- Free online English lessons with a native speaker.
- Generous referral program.
- Training, internal workshops, and participation in international professional conferences and corporate events.
Elastyczne godziny
Opieka zdrowotna
Karta sportowa
Kursy językowe
SOFTSWISS
18 aktywnych ofert