3 авг

application security engineer

выше рынка на 29,9%
вакансия 445 889 ₽
в среднем 343 365 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

генерация резюме под вакансию

Загрузи резюме в профиль, чтобы сгенерировать временное CV под эту вакансию

сопроводительное письмо

Загрузи резюме в профиль, а нейросеть определит твою категорию. Затем ты сможешь генерировать сопроводительные письма для вакансий этой категории

описание

PandaDoc provides an all-in-one document workflow automation platform that helps growing organizations create, manage, and sign digital documents, including proposals, quotes, and contracts.

задачи

  • Review, test, and monitor applications to identify security weaknesses;
  • Manage vulnerabilities from discovery through remediation with engineering teams;
  • Respond to infrastructure security alerts and perform hardening, including reviewing roles and permissions across services and APIs;
  • Participate in incident response and root cause analysis;
  • Analyze and monitor relevant security threats and prevention measures based on industry trends and standards;
  • Partner with product, development, and infrastructure teams to embed security requirements into development processes;
  • Integrate and operate automated security testing across the development lifecycle, including SAST, DAST, SCA, secrets detection, container, and supply chain security;
  • Develop security automation and tooling to scale security across engineering;
  • Drive threat modeling and secure-by-design practices across services;
  • Assess the overall security posture, identify risks, and provide recommendations to strengthen it;
  • Assist in addressing emerging AI security threats as PandaDoc deploys AI in its product and for internal use.

требования

  • 3+ Years of experience with application security tools such as SAST/SCA, DAST, WAF, CI/CD security, and penetration testing;
  • 2+ Years of cloud security experience implementing security controls and best practices in AWS, GCP, or Microsoft Azure;
  • Strong background in web application security, including OWASP Top 10, CWE Top 25, attack vectors, and mitigations;
  • Good understanding of access control and identity management principles, including SAML 2.0, OAuth, OIDC, and JWT;
  • Practical skills building security automation and tooling with Python, Bash, or equivalent languages;
  • Experience implementing DevSecOps practices across the SDLC;
  • Familiarity with containerized, Kubernetes-based environments and their security;
  • Solid interpersonal, written, and verbal communication skills;
  • Upper-Intermediate English level (B2+).

условия

  • Monthly base salary of 21,000 PLN to 24,750 PLN;
  • Comprehensive healthcare coverage through LuxMed for employees and their families;
  • UNUM life insurance for employees and their families;
  • Multisport Card for fitness and wellness activities;
  • Onboarding benefit allowance for necessary work equipment and setup;
  • 6 Self-care days beyond standard Polish vacation entitlements;
  • Wellness, learning, and development budgets;
  • Employees may be able to purchase company stock or receive annual bonuses.

Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.

прозрачные зарплаты в IT

Анонимные данные по зарплатам и грейдам

Посмотреть
График динамики зарплат
Откликнуться Добавить в трекер

Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.