
Application Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Italy.
• Establish security requirements and design application architectures utilizing a *secure-by-default* methodology.
• Perform threat modeling, code reviews, and penetration testing on cloud-based web and mobile applications to proactively uncover vulnerabilities.
• Execute, oversee, and automate SAST/DAST/SCA security measures and WAF rules to ensure scalable protection.
• Collaborate with Product teams to guarantee strong security measures and promote a security-first development culture.
• Engage in the investigation, management, and resolution of security alerts.
• Work together on all key activities and initiatives within the Security Engineering team.
• In-depth understanding of web/mobile security vulnerabilities, AI security threats, and industry standards (e.g., OWASP Top 10, CWE).
• Practical experience with threat modeling frameworks (e.g., STRIDE), code reviews, penetration testing, and SAST/DAST/SCA tools.
• Proficient in scripting/programming (e.g., Python, Rust) and familiar with CI/CD systems and Infrastructure as Code (e.g., Pulumi).
• Willingness to participate in on-call shifts to ensure continuous 24x7 security monitoring and support.
• Self-driven and proactive problem solvers with strong English communication skills and experience in Agile environments.
• Enjoy full flexibility – work from home, the office, or a combination of both.
• Work remotely from anywhere for up to 30 days a year.
• Access to learning resources, mentorship, and a personalized growth plan.
• Private healthcare.
• Discounts on gym memberships.
• Wellbeing programs.
• Mental health support.
Red River
Gainwell Technologies
Zocdoc
Capital Project Intelligence
Get handpicked remote jobs straight to your inbox weekly.