application security engineer in application security
ориентир по рынку
вакансия
зп не указана
в среднем
323 895 ₽
мэтч
Загрузи резюме, чтобы видеть мэтчи с вакансией
подготовься к отклику
ai-инструменты
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
описание
The role focuses on reducing security risk across web applications and APIs throughout the software development lifecycle, helping teams identify real risks, reduce false positives, and build and ship secure software efficiently.
задачи
Perform security assessments of web applications, APIs, services, and supporting components
Facilitate threat modeling and review architectures and technical designs from a security perspective
Conduct secure code reviews and identify vulnerabilities and insecure implementation patterns
Validate findings from automated tools, reduce false positives, and prioritize issues based on exploitability and business impact
Provide actionable remediation guidance and secure implementation recommendations
Track findings through remediation and retesting in collaboration with development teams
Advise teams on authentication, authorization, session management, input validation, data protection, cryptography, secrets handling, and API security controls
Contribute to secure SDLC practices, security standards, guidelines, and reusable security patterns
Communicate security risks and recommendations to technical and non-technical stakeholders
требования
Hands-on experience in application security or product security
Strong knowledge of web application and API security, including OWASP Top 10 and common vulnerability classes
Understanding of threat modeling and secure software design principles
Strong knowledge of authentication, authorization, session management, input validation, cryptography, secrets handling, and data protection
Hands-on experience with one or more application security technologies, such as SAST, DAST, IAST, SCA, or secrets-scanning tools
Ability to validate security findings, distinguish actionable risks from false positives, and prioritize remediation
Ability to read and understand code in at least one programming language, such as Java, C#, JavaScript/TypeScript, Python, or Go
Familiarity with modern application architectures, APIs, distributed services, and common software development practices
Strong communication skills and ability to provide practical guidance to engineering teams
Будет плюсом: DevSecOps practices, integrating application security tools and security gates into CI/CD pipelines, creating or improving secure SDLC processes, security standards and developer-facing secure coding guidance, cloud application security concepts (AWS, Microsoft Azure, or Google Cloud), IAM and application identity concepts (SSO, OAuth 2.0, OpenID Connect, SAML), containers/Kubernetes or Infrastructure as Code security (Terraform and similar), relevant security certifications (CSSLP, CISSP) or equivalent practical expertise