Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
SOFTSWISS supplies leading iGaming software solutions and is an equal opportunity employer.
задачи
Partner with product teams during the design phase to lead threat modeling and risk assessments sessions, translating complex security threats into clear, actionable security requirements;
Perform in-depth manual code reviews on critical applications to identify complex logical vulnerabilities as part of white-box security assessment;
Plan, design, implement, automate and support AppSec tools;
Contribute to building company-wide processes for secure code development and deployment;
Triage identified security vulnerabilities, provide clear and actionable descriptions and ensure these findings are properly addressed and mitigated;
Manage the bug bounty program, collaborate with researches and internal teams to resolve the discovered vulnerabilities;
Partner with Dev/QA teams throughout the development lifecycle to enhance the application’s security posture by providing expert consulting, continuous knowledge sharing, and actionable security guidance.
требования
5+ Years of experience in Application Security;
Knowledge of secure development processes and best practices;
Deep understanding of web application security mechanisms;
Deep understanding of common web application vulnerabilities and the most effective ways to prevent them;
Knowledge of secure system/application architecture and design principles;
Understanding of modern threats to high-performance web applications that are used by millions of users daily;
Understanding of modern authentication/authorisation patterns;
Practical hands-on expertise in identifying vulnerabilities through security assessment and secure code review, coupled with the ability to perform deep root-cause analysis to drive systemic fixes;
University degree in Computer Science, Information Security, or related field, or equivalent combination of education and experience;
English and Russian proficiency at an upper-intermediate level (B2+);
Nice to have: passion about programming, technical knowledge of network and operating systems security, hands-on DevSecOps experience, practice of participation in bug bounty programs and/or CTFs, deep knowledge of SAST/DAST tools including customisation, relevant certifications.
условия
Private health insurance;
Sports benefits;
Comprehensive Mental Health Program;
Free English lessons (online);
Local language courses;
Paid time off;
Maternity leave support;
Referral program rewards;
Upskilling, internal workshops, and participation in professional conferences and corporate events.