Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой — после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Remote role excluding Belarus and Russia.
Salmon is an international technology-driven financial company operating in Southeast Asia's fintech sector.
задачи
Build or substantially improve a secure SDLC in a fast-moving product org;
Run threat modeling on real product features and influence design decisions as a result;
Own vulnerability management end-to-end including triage, remediation tracking, SLA management, and risk acceptance;
Conduct hands-on mobile security testing for iOS and/or Android in a production context;
Reduce exposure to modern supply chain attack vectors at the tooling and process level;
Write Python or Bash to automate repetitive security work.
требования
7+ Years in application security, with meaningful ownership over both technical work and process;
Understand modern supply chain attack vectors like compromised packages including npm and PyPI, malicious IDE plugins, typosquatting, and dependency confusion;
Knowledge of SAST, DAST, and SCA in CI/CD pipelines;
Expertise in API security including authentication flows, token handling, and common abuse patterns;
Practical application of OWASP ASVS and MASVS for mobile security;
Experience with SBOM generation and dependency risk management;
Skills in secrets management including detection, remediation, and structural prevention;
Working knowledge of AWS and containers sufficient to understand where application risks extend into infrastructure;
Nice to have: familiarity with relevant security frameworks and tools.
Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.
Про зарплаты
Анонимные данные по зарплатам и грейдам. Можно сверить вилку с рынком.
Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.