9 окт

application security engineer in application security

ориентир по рынку
вакансия зп не указана
в среднем 323 895 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовься к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме

описание

The role focuses on reducing security risk across web applications and APIs throughout the software development lifecycle, helping teams identify real risks, reduce false positives, and build and ship secure software efficiently.

задачи

  • Perform security assessments of web applications, APIs, services, and supporting components
  • Facilitate threat modeling and review architectures and technical designs from a security perspective
  • Conduct secure code reviews and identify vulnerabilities and insecure implementation patterns
  • Validate findings from automated tools, reduce false positives, and prioritize issues based on exploitability and business impact
  • Provide actionable remediation guidance and secure implementation recommendations
  • Track findings through remediation and retesting in collaboration with development teams
  • Advise teams on authentication, authorization, session management, input validation, data protection, cryptography, secrets handling, and API security controls
  • Contribute to secure SDLC practices, security standards, guidelines, and reusable security patterns
  • Communicate security risks and recommendations to technical and non-technical stakeholders

требования

  • Hands-on experience in application security or product security
  • Strong knowledge of web application and API security, including OWASP Top 10 and common vulnerability classes
  • Practical experience with security assessments, secure design reviews, and/or secure code reviews
  • Understanding of threat modeling and secure software design principles
  • Strong knowledge of authentication, authorization, session management, input validation, cryptography, secrets handling, and data protection
  • Hands-on experience with one or more application security technologies, such as SAST, DAST, IAST, SCA, or secrets-scanning tools
  • Ability to validate security findings, distinguish actionable risks from false positives, and prioritize remediation
  • Ability to read and understand code in at least one programming language, such as Java, C#, JavaScript/TypeScript, Python, or Go
  • Familiarity with modern application architectures, APIs, distributed services, and common software development practices
  • Strong communication skills and ability to provide practical guidance to engineering teams
  • Будет плюсом: DevSecOps practices, integrating application security tools and security gates into CI/CD pipelines, creating or improving secure SDLC processes, security standards and developer-facing secure coding guidance, cloud application security concepts (AWS, Microsoft Azure, or Google Cloud), IAM and application identity concepts (SSO, OAuth 2.0, OpenID Connect, SAML), containers/Kubernetes or Infrastructure as Code security (Terraform and similar), relevant security certifications (CSSLP, CISSP) or equivalent practical expertise

условия

  • Условий в вакансии нет

Глобальная компания в сфере digital engineering, product development и технологического консалтинга.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.

Спроси Хайрика про вакансию

Сверит с твоим резюме, подскажет вилку и вопросы на собесе.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.