сегодня

application security engineer

ориентир по рынку
вакансия зп не указана
в среднем 343 365 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Moderna builds an mRNA technology platform and infrastructure for creating and delivering medicines. The company develops scientific capabilities and products aimed at changing the future of medicine.

задачи

  • Lead the enterprise code security strategy and manage the primary code security platform;
  • Lead code security architecture efforts for custom-built applications and services, including secure design reviews, architecture reviews, and risk assessments across the software development lifecycle;
  • Lead risk assessments across on-premises and cloud environments, identify vulnerabilities, and recommend mitigation strategies for COTS products and custom in-house services;
  • Conduct threat modeling exercises for applications, APIs, platforms, and supporting infrastructure to identify abuse paths and control gaps;
  • Drive secure software development practices, including code security principles, dependency risk management, secrets handling, and secure-by-design engineering patterns;
  • Assess and advise on security risks across cloud, network, and AI-enabled architectures;
  • Identify and remediate security misconfigurations across applications and cloud environments in collaboration with security operations and platform teams;
  • Provide architectural guidance and technical leadership across multiple security domains.

требования

  • 4+ Years of experience in cybersecurity, with strong expertise in application and code security architecture;
  • Experience reviewing custom-built applications and services for security risks, secure design, code-level weaknesses, and architectural flaws;
  • Strong understanding of secure software development, threat modeling, dependency and package risk, secrets management, and common application security vulnerabilities;
  • Ability to work effectively with software engineers and architects and translate security concerns into practical guidance;
  • Broad security knowledge across cloud, network, and AI domains;
  • Experience assessing cloud security architectures and identifying misconfigurations in modern hybrid environments;
  • Working knowledge of network security fundamentals, including segmentation, core protocols, and common enterprise security controls;
  • Familiarity with AI security risks and architectural considerations related to application and data security;
  • Strong leadership and communication skills, including the ability to influence technical decisions and explain complex security risks to senior stakeholders;
  • Exceptional analytical, critical thinking, and problem-solving skills with a strategic mindset.

условия

  • Competitive healthcare and voluntary benefit programs;
  • Fitness, mindfulness, and mental health support;
  • Family building benefits, including fertility, adoption, and surrogacy support;
  • Generous paid time off, including vacation, bank holidays, volunteer days, sabbatical, global recharge days, and a discretionary year-end shutdown;
  • Savings and investment programs;
  • Location-specific perks and extras;
  • Benefits may vary depending on the nature of employment and the country of work;
  • In-office 70/30 work model;
  • Smoke-free, alcohol-free, and drug-free work environment.

Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Откликнуться Добавить в трекер

Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.