Application Security Engineer
Brak informacji o wynagrodzeniu
MidFull-time
#438665·Dodano 10 dni temu·6
Źródło: nofluffjobs.comTech Stack / Keywords
SecurityAPIStorageGDPROAuthRBACCMSTestingCISSPOSCP
Firma i stanowisko
We are looking for an Application Security Engineer to join a greenfield digital news platform build for a major international news brand. The platform handles extreme traffic during breaking-news events and integrates CMS, video pipeline, advertising, personalization services, and public-facing APIs. Security is embedded as an engineering requirement throughout all delivery phases.
Wymagania
- 5+ years of experience in application security, security engineering, or closely related roles.
- Experience performing threat modelling and architecture security reviews on complex, multi-component platforms.
- Strong knowledge of authentication and authorization patterns including OAuth, OIDC, RBAC, and privileged access management.
- Hands-on experience validating API security and reviewing integration patterns across third-party services.
- Solid understanding of secrets management, credential handling, and token lifecycle best practices.
- Experience supporting or coordinating vulnerability scanning and penetration testing programmes.
- Knowledge of encryption standards and secure data handling practices across storage and transit.
- Familiarity with GDPR and privacy-by-design engineering requirements.
- Ability to produce clear remediation guidance and security acceptance documentation for engineering and delivery teams.
Nice to have:
- Experience securing composable CMS or media platform architectures like AEM or Amplience.
- Background working on high-traffic, public-facing platforms prioritizing availability and security.
- Experience with security logging and monitoring tooling such as SIEM, alerting, and incident response playbooks.
- Familiarity with third-party vendor security assessment processes.
- Relevant certifications such as CISSP, OSCP, CEH, or equivalent.
- Experience working within a phased, full-lifecycle delivery programme alongside engineering and architecture teams.
Obowiązki
- Define and validate application and platform security controls across all delivery phases.
- Perform architecture and threat-model reviews at design stage and as the platform evolves.
- Review authentication, authorization, and privileged-access controls across CMS, APIs, and integrated services.
- Validate API and integration security across a composable, multi-vendor platform architecture.
- Review secrets, credentials, and token-management practices across the full stack.
- Support vulnerability scanning and penetration-testing activities, coordinating findings and remediation.
- Validate encryption and secure data handling across storage, transit, and third-party integrations.
- Review security logging, monitoring, and incident-response requirements.
- Support GDPR and privacy engineering requirements throughout delivery.
- Conduct third-party security assessments for integrated services and vendors.
- Provide remediation guidance and produce security acceptance evidence ahead of launch.
Benefity
- Private healthcare
- Sport subscription
- International projects
- Free coffee
- Playroom
- Shower
- Free snacks
- Free beverages
- No dress code
Opieka zdrowotna
Karta sportowa
Napoje w biurze
Darmowe przekąski
Prysznic
Tooploox
3 aktywne oferty