вчера

application security engineer

ориентир по рынку
вакансия зп не указана
в среднем 236 992 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

генерация резюме под вакансию

Загрузи резюме в профиль, чтобы сгенерировать временное CV под эту вакансию

сопроводительное письмо

Загрузи резюме в профиль, а нейросеть определит твою категорию. Затем ты сможешь генерировать сопроводительные письма для вакансий этой категории

описание

Rivian manufactures emissions-free Electric Adventure Vehicles and focuses on sustainable transportation solutions. The company challenges conventional industry standards by reframing complex problems and developing innovative, secure-by-design technologies.

задачи

  • Review source code and application architectures to identify and communicate security vulnerabilities to development teams;
  • Drive the adoption of Software Bill of Materials (SBOM) to ensure software supply chain visibility, license compliance, and vulnerability tracking;
  • Implement and manage automated Software Composition Analysis (SCA) to identify and remediate vulnerabilities in open-source and third-party libraries;
  • Develop and support automated security tooling and agentic security workflows within CI/CD pipelines;
  • Work closely with the penetration testing team to identify and implement remediations for security vulnerabilities;
  • Support the implementation of security configurations and countermeasures based on emerging threats and industry trends.

требования

  • 4+ Years of application security experience;
  • Proficiency with GraphQL, AWS, React, Java, Node.js, Python, and containerization technologies like Docker and Kubernetes;
  • Hands-on experience with reviewing and remediating common SAST and SCA vulnerabilities;
  • Strong hands-on coding or scripting skills for building security utilities and automation;
  • Strong problem-solving and decision-making capabilities;
  • Nice to have: Experience in the automotive, manufacturing, or technology industries, experience with cloud native and Kubernetes hosted applications, experience with Gitlab CI/CD or other DevOps technologies, experience identifying and mitigating AI-specific vulnerabilities.

условия

  • No conditions specified

Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.

прозрачные зарплаты в IT

Анонимные данные по зарплатам и грейдам

Посмотреть
График динамики зарплат
Откликнуться Добавить в трекер

Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.