Application Security Engineer

Brak informacji o wynagrodzeniu
MidFull-time
#438665·Dodano 10 dni temu·6
Źródło: nofluffjobs.com
Aplikuj teraz

Tech Stack / Keywords

SecurityAPIStorageGDPROAuthRBACCMSTestingCISSPOSCP

Firma i stanowisko

We are looking for an Application Security Engineer to join a greenfield digital news platform build for a major international news brand. The platform handles extreme traffic during breaking-news events and integrates CMS, video pipeline, advertising, personalization services, and public-facing APIs. Security is embedded as an engineering requirement throughout all delivery phases.

Wymagania

  • 5+ years of experience in application security, security engineering, or closely related roles.
  • Experience performing threat modelling and architecture security reviews on complex, multi-component platforms.
  • Strong knowledge of authentication and authorization patterns including OAuth, OIDC, RBAC, and privileged access management.
  • Hands-on experience validating API security and reviewing integration patterns across third-party services.
  • Solid understanding of secrets management, credential handling, and token lifecycle best practices.
  • Experience supporting or coordinating vulnerability scanning and penetration testing programmes.
  • Knowledge of encryption standards and secure data handling practices across storage and transit.
  • Familiarity with GDPR and privacy-by-design engineering requirements.
  • Ability to produce clear remediation guidance and security acceptance documentation for engineering and delivery teams.

Nice to have:

  • Experience securing composable CMS or media platform architectures like AEM or Amplience.
  • Background working on high-traffic, public-facing platforms prioritizing availability and security.
  • Experience with security logging and monitoring tooling such as SIEM, alerting, and incident response playbooks.
  • Familiarity with third-party vendor security assessment processes.
  • Relevant certifications such as CISSP, OSCP, CEH, or equivalent.
  • Experience working within a phased, full-lifecycle delivery programme alongside engineering and architecture teams.

Obowiązki

  • Define and validate application and platform security controls across all delivery phases.
  • Perform architecture and threat-model reviews at design stage and as the platform evolves.
  • Review authentication, authorization, and privileged-access controls across CMS, APIs, and integrated services.
  • Validate API and integration security across a composable, multi-vendor platform architecture.
  • Review secrets, credentials, and token-management practices across the full stack.
  • Support vulnerability scanning and penetration-testing activities, coordinating findings and remediation.
  • Validate encryption and secure data handling across storage, transit, and third-party integrations.
  • Review security logging, monitoring, and incident-response requirements.
  • Support GDPR and privacy engineering requirements throughout delivery.
  • Conduct third-party security assessments for integrated services and vendors.
  • Provide remediation guidance and produce security acceptance evidence ahead of launch.

Benefity

  • Private healthcare
  • Sport subscription
  • International projects
  • Free coffee
  • Playroom
  • Shower
  • Free snacks
  • Free beverages
  • No dress code
Opieka zdrowotna
Karta sportowa
Napoje w biurze
Darmowe przekąski
Prysznic
Tooploox

Tooploox

3 aktywne oferty

Zobacz wszystkie oferty
Aplikuj teraz