
Application Security Engineer
Posted Jun 3

Posted Jun 3
This is a fully remote position, open to applicants in Portugal.
β’ Take ownership of and manage our Bug Bounty programs: assess reports, verify findings, and reproduce Proofs of Concept (PoCs).
β’ Collaborate with developers and product owners to recommend and aid in the resolution of security issues.
β’ Write or review pull requests to address security vulnerabilities directly within the codebase.
β’ Validate findings from external penetration tests and incorporate them into the development backlog.
β’ Contribute to threat modeling, code reviews, and discussions regarding security design.
β’ Support the Secure Development Lifecycle (SAST, dependency scanning, security automation in CI/CD).
β’ Conduct lightweight penetration testing for new features and releases as necessary.
β’ Maintain comprehensive documentation to support Application Security processes.
β’ Facilitate security communications among Security, Developers, and Product to expedite the resolution of security tickets.
β’ Prior experience as a developer (any modern backend or frontend stack).
β’ Practical security experience through bug bounty programs, Capture The Flags (CTFs), or penetration testing, along with relevant tools (e.g., Burp Suite).
β’ Strong understanding of common application vulnerabilities (OWASP Top 10, SSRF, IDOR, etc.).
β’ Familiarity with SAST/DAST tools (e.g., SonarQube, Snyk).
β’ Experience working collaboratively with developers and product teams.
β’ Excellent problem-solving and communication skills with a proactive βfind and fixβ approach.
β’ International team comprising 40+ nationalities (and counting!) π
β’ Remote-first policy with a headquarters located in Paris πΌ
β’ Dynamic startup environment with opportunities for career advancement πͺ΄
β’ Open-minded culture that values diversity π½
β’ Supportive and curious team focused on feedback and a DIY mindset π€ π
β’ Generous Paid Time Off to ensure you have time for what matters most β€οΈπ‘
β’ Remote perks designed to enhance your working experience π
β’ In-person social events to celebrate our achievements ποΈ
β’ Full coverage of your health insurance contribution paid by Swapcard π₯
β’ Work-from-home budget (one-time contribution for equipment in addition to your initial setup) ποΈ
β’ Co-working space budget to facilitate remote work in professional settings πΌ
β’ Learning budget to assist you in developing new and existing skills π€
β’ Mental health care initiatives to promote your well-being π§
Constructor Tech
Constructor Tech
Nethermind
Get handpicked remote jobs straight to your inbox weekly.