сегодня

application security engineer for B2B SaaS

выше рынка на 16,7%
вакансия 383 484 ₽
в среднем 328 556 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Nebius Academy, powered by TripleTen, provides assessments and training for tech companies and aspiring professionals worldwide. It focuses on data science, machine learning, and generative AI to help companies develop employees’ skills and drive innovation.

задачи

  • Own application and product security end to end, from design reviews and threat modelling to vulnerability remediation and follow-up
  • Partner with product and platform teams to embed security into the development lifecycle
  • Build and improve CI/CD security controls, including SAST, dependency, secrets, container, and IaC scanning
  • Review application designs and code where security risk is meaningful, and turn recurring findings into secure defaults, shared libraries, lint rules, and CI gates
  • Drive vulnerability management across application code and cloud posture, including triage, risk-based prioritisation, remediation timelines, and external pentest findings
  • Strengthen security in multitenant B2B systems, including tenant isolation, authentication, authorization, RBAC / ABAC, and access controls
  • Improve cloud and Kubernetes security across AWS environments, including IAM, secrets management, network boundaries, and workload hardening
  • Translate GDPR, SOC 2, and ISO 27001 requirements into practical engineering controls and system properties
  • Develop and support a security champions programme to help engineering teams adopt secure practices
  • Address security risks in AI and LLM-powered features, including prompt injection, data leakage, and untrusted model output

требования

  • 5+ Years of engineering experience, including at least 2 years focused on Application Security or Product Security
  • Strong software engineering background and ability to read, review, and write production code
  • Practical knowledge of web application security, including OWASP Top 10, ASVS, authentication and session management, OAuth2 / OIDC / SAML, and authorization issues such as IDOR and broken access control
  • Experience securing multitenant or B2B SaaS products, including tenant isolation, RBAC / ABAC, and access control models
  • Hands-on experience embedding security into CI/CD, including SAST, SCA, secrets scanning, container scanning, and IaC scanning
  • Experience with threat modelling, secure design reviews, and secure code reviews in collaboration with product and engineering teams
  • Experience managing vulnerabilities based on risk, criticality, and exploitability, including remediation prioritisation and escalation
  • Working knowledge of AWS and Kubernetes security, including IAM, secrets management, network boundaries, and workload hardening
  • Strong communication skills and ability to explain security risks clearly to engineers, product managers, and auditors
  • Fluent Russian and English at B2 level or above
  • Будет плюсом: Python experience, building a DevSecOps practice from scratch, running or participating in a Security Champions programme, hands-on penetration testing, securing LLM-powered or AI products, SOC 2 or ISO 27001 experience from an engineering perspective, software supply chain security knowledge including SBOMs, SLSA, and image signing

условия

  • Competitive compensation: 4000-6000 EUR Gross per month
  • A supportive and proactive work environment
  • Modern digital tools for seamless collaboration
  • Tangible results measured by student success

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.