
Application Security Engineer
Posted Sep 12

Posted Sep 12
This is a fully remote position, open to applicants in Serbia.
• Conduct both manual and automated security assessments for web applications and APIs.
• Execute application penetration testing to uncover vulnerabilities, security weaknesses, and configuration issues.
• Record findings, offer remediation recommendations, and assign risk ratings in comprehensive technical reports.
• Verify remediation efforts through re-testing processes.
• Engage in threat modeling exercises and participate in security design evaluations.
• Carry out security-focused reviews of the source code for internally developed applications.
• Assist developers in understanding and addressing identified vulnerabilities.
• Foster secure coding practices and enhance security awareness among development teams.
• Aid in the integration and functioning of security testing within CI/CD pipelines.
• Support the deployment and optimization of SAST, DAST, SCA, and secrets detection controls.
• Contribute to security automation projects utilizing Jenkins, GitLab, and Bitbucket.
• Track and manage vulnerabilities discovered during security testing activities.
• Collaborate with development teams to prioritize and resolve findings.
• Evaluate application security risks and suggest appropriate mitigation strategies.
• Work alongside development, architecture, infrastructure, and Information Security teams.
• Assist in security reviews prior to production deployments.
• Contribute to the ongoing enhancement of application security standards, processes, and procedures.
• At least 3 years of experience in application security, penetration testing, software development, or a related information security role.
• Proven experience in conducting web application security assessments and penetration testing.
• Knowledge of secure software development methodologies.
• Experience in reviewing source code and identifying typical security vulnerabilities.
• In-depth knowledge of OWASP Top 10, CWE, NIST security guidelines, and secure coding practices.
• Familiarity with web technologies, APIs, databases, and networking concepts.
• Proficiency in programming languages such as Java, .NET/C#, Python, JavaScript, or Perl.
• Understanding of authentication, authorization, and session management principles.
• Experience with tools including Burp Suite, OWASP ZAP, Nessus, Metasploit, Wireshark, as well as SAST and DAST tools.
• Exposure to Jenkins, GitLab, Bitbucket, and Agile development environments.
• Strong analytical and problem-solving capabilities.
• Excellent verbal and written communication skills.
• Ability to collaborate effectively within cross-functional teams.
• Proactive and strategic thinker who can transform concepts into actionable plans.
• Champions security enhancement initiatives while recognizing business priorities and constraints.
• Proven experience in mentoring, coaching, and supporting the development of a diverse and distributed team.
• Fully remote work setup.
• Monday to Friday, 40-hour workweek.
• Working hours from 1PM–9PM CET.
• Opportunity to gain knowledge and develop skills in application security and DevSecOps practices.
3M
Lenze
Compose.ly
GE Vernova
Get handpicked remote jobs straight to your inbox weekly.