
Application Security Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Ukraine.
• Collaborate with development teams, Site Reliability Engineering, and other stakeholders to enhance security best practices throughout the Software Development Life Cycle (SDLC).
• Independently identify and implement security improvements.
• Manage, implement, and automate processes for vulnerability management.
• Prioritize and address vulnerabilities identified through internal scans, penetration tests, and bug bounty programs.
• Conduct threat modeling, code audits, and design reviews in collaboration with engineers.
• Offer actionable security recommendations and practical solutions.
• Establish and automate threat hunting capabilities.
• Improve logging capabilities related to security incidents.
• Integrate and manage both dynamic and static code analysis tools.
• Ensure the effective operation of security tools within the development pipeline.
• Minimum of 4 years of experience in secure development or application security.
• Comprehensive understanding of security concepts, including authentication and web architecture.
• Proficient in Node.js, Go, or similar technologies.
• Experience managing bug bounty, penetration testing, and vulnerability scanning initiatives.
• Skilled in setting up and maintaining SAST, DAST, IAST, and SCA tools.
• Familiar with assessment tools such as Burp, ZAP, Qualys, and Nessus.
• Experience in building and maintaining Web Application Firewall (WAF) solutions.
• Knowledge of industry security practices, standards, and regulations such as FedRAMP, SOC2, and HIPAA is advantageous.
• Familiarity with GCP/AWS and Kubernetes infrastructure security is a plus.
• Self-motivated and results-oriented, with the ability to recognize and accomplish necessary tasks.
• Capable of respectfully challenging colleagues and managers in the pursuit of excellence.
• Strong sense of urgency and an action-oriented approach.
• Able to collaborate effectively and adapt to changing priorities.
• Comfortable with asynchronous communication tools such as Slack, email, and Zoom.
• Health insurance from the first day of employment, irrespective of the probationary period.
• Paid Christmas holidays from December 25 to December 31.
• Collaboration with Superhumans center and Veteran HUB.
• Access to psychological counseling services provided by the Veteran Hub.
• Internal policies that promote a supportive environment for military personnel and veterans.
Hotel Engine
Bolder Apps
Planar
AcuityMD
Get handpicked remote jobs straight to your inbox weekly.