application security engineer for cloud software

ориентир по рынку
вакансия зп не указана
в среднем 343 365 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Altium Limited, part of the Renesas Group, is a global software company accelerating electronics innovation through a cloud-based platform that unites stakeholders and phases of electronics development. Its digital platforms support PCB designers, supply chain, and manufacturing teams in collaborating more effectively.

задачи

  • Build and maintain security regression test suites for critical application flows;
  • Ensure fixed vulnerabilities are permanently prevented from recurring;
  • Integrate security regression testing into CI/CD pipelines;
  • Define coverage targets for security-critical areas, including authentication, access control, APIs, and data flows;
  • Lead threat modeling sessions for existing system components, new features, and architectural changes;
  • Identify attack surfaces, abuse cases, and trust boundaries;
  • Translate threats into test cases, security requirements, and mitigation plans;
  • Establish threat modeling as a continuous lifecycle activity;
  • Perform manual and automated security testing that simulates real attacker behavior;
  • Focus on high-impact vulnerabilities and validate exploitability and business impact;
  • Partner with engineering teams to reproduce issues, prioritize fixes, and validate remediation;
  • Continuously assess the platform against OWASP Top 10 categories;
  • Discover context-specific vulnerabilities, logic flaws, and abuse paths beyond DAST/SAST tooling;
  • Review new features and changes for security risks;
  • Ensure product changes are threat-modeled and covered by regression tests;
  • Act as a security gatekeeper while enabling teams with guidance and tooling;
  • Contribute to secure-by-design practices;
  • Support developers in understanding and fixing vulnerabilities;
  • Scale security through reusable patterns, automation, and security guidance.

требования

  • 5+ Years of experience in Application or Product Security;
  • Bachelor’s Degree or equivalent of 12 years of work experience;
  • Strong hands-on experience in web application security testing, API security, and threat modeling methodologies;
  • Deep understanding of OWASP Top 10;
  • Experience with manual penetration testing, security regression testing, and CI/CD security integration;
  • Ability to identify business logic vulnerabilities;
  • Strong understanding of authentication, authorization, session management, multi-tenant architectures, and cloud-native systems;
  • Nice to have: experience in SaaS or multi-tenant platforms, familiarity with bug bounty programs, red teaming, and security automation frameworks, knowledge of AWS and identity systems and federation including SSO and MFA, software engineering background with the ability to read and write code.

условия

  • Competitive benefits package alongside salary.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.