24 июл

application security engineer

ориентир по рынку
вакансия зп не указана
в среднем 328 556 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

SOFTSWISS supplies leading iGaming software solutions and is an equal opportunity employer.

задачи

  • Partner with product teams during the design phase to lead threat modeling and risk assessments sessions, translating complex security threats into clear, actionable security requirements;
  • Perform in-depth manual code reviews on critical applications to identify complex logical vulnerabilities as part of white-box security assessment;
  • Plan, design, implement, automate and support AppSec tools;
  • Contribute to building company-wide processes for secure code development and deployment;
  • Triage identified security vulnerabilities, provide clear and actionable descriptions and ensure these findings are properly addressed and mitigated;
  • Manage the bug bounty program, collaborate with researches and internal teams to resolve the discovered vulnerabilities;
  • Partner with Dev/QA teams throughout the development lifecycle to enhance the application’s security posture by providing expert consulting, continuous knowledge sharing, and actionable security guidance.

требования

  • 5+ Years of experience in Application Security;
  • Knowledge of secure development processes and best practices;
  • Deep understanding of web application security mechanisms;
  • Deep understanding of common web application vulnerabilities and the most effective ways to prevent them;
  • Knowledge of secure system/application architecture and design principles;
  • Understanding of modern threats to high-performance web applications that are used by millions of users daily;
  • Understanding of modern authentication/authorisation patterns;
  • Practical hands-on expertise in identifying vulnerabilities through security assessment and secure code review, coupled with the ability to perform deep root-cause analysis to drive systemic fixes;
  • University degree in Computer Science, Information Security, or related field, or equivalent combination of education and experience;
  • English and Russian proficiency at an upper-intermediate level (B2+);
  • Nice to have: passion about programming, technical knowledge of network and operating systems security, hands-on DevSecOps experience, practice of participation in bug bounty programs and/or CTFs, deep knowledge of SAST/DAST tools including customisation, relevant certifications.

условия

  • Private health insurance;
  • Sports benefits;
  • Comprehensive Mental Health Program;
  • Free English lessons (online);
  • Local language courses;
  • Paid time off;
  • Maternity leave support;
  • Referral program rewards;
  • Upskilling, internal workshops, and participation in professional conferences and corporate events.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.