
Application Security Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Slovakia.
• Take ownership of and maintain application security pipelines: SCA (GitHub/Trivy), DAST (Nessus, Acunetix, Wiz), and SAST.
• Assess findings from security tools and facilitate their remediation.
• Conduct penetration tests on new platform features, internal applications, slots, and live games.
• Execute basic red team activities, including reviews of leaked credentials and external attack surface audits.
• Analyze complex authentication flows with third parties for cryptographic and security vulnerabilities.
• Review and assess application code for security concerns, primarily in NestJS and .NET.
• Assume responsibility for security risks in existing code and applications.
• Serve as the application-level security authority during incident response and provide hotfixes as necessary.
• Compile quarterly SAST/DAST vulnerability scan reports for stakeholders and regulators.
• Engage in audit meetings.
• Manage the Secure Coding and Application Security domains within the ISMS.
• Regularly meet with development teams to understand upcoming features and provide guidance on secure design.
• Over 5 years of experience as an Application Security Engineer.
• Background in red teaming, penetration testing, application security, and software development.
• Proven ability to independently identify vulnerabilities in web and desktop applications, prioritize them, and implement fixes when necessary.
• Strong foundation in data structures, algorithms, and systems architecture design.
• Previous experience in security testing with Kafka, Redis, BullMQ, or PubSub as messaging/streaming tools.
• Capable of coding independently and navigating unfamiliar web application frameworks.
• Experience utilizing AI tools for vulnerability hunting.
• Effective communication skills to collaborate with developers and convert findings into practical, actionable recommendations.
• Preferred: CRTO, OSCP, or OSWE certifications or equivalent.
• Preferred: Knowledge of cloud platforms such as GCP/AWS.
• Preferred: Understanding of CI/CD pipelines.
• Preferred: Hands-on experience with Trivy, Nessus, Acunetix, or Wiz.
• Preferred: Experience in iGaming or another regulated industry.
• Competitive salary in EUR with annual performance evaluations to acknowledge your growth.
• Flexible remote work options.
• Medical insurance coverage.
• Access to psychologist support.
• Clubs for Polish and Slovak speakers.
• 20 days of paid vacation per year.
• Additional 10 paid days off.
• 10 paid sick leave days.
• All national holidays recognized in your country.
• Reimbursement for courses, training, and certifications.
• Support for language classes, sports activities, massages, or life coaching services.
Hotel Engine
Bolder Apps
Planar
AcuityMD
Get handpicked remote jobs straight to your inbox weekly.