5 сен

application security engineer in application security

ориентир по рынку
вакансия зп не указана
в среднем 343 365 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Extia is a consulting company specialized in IT and digital sectors. Founded in 2007, it combines performance and workplace well-being and operates internationally with more than 2,500 employees.

задачи

  • Contribute to the application security strategy and roadmap within the organization;
  • Mentor and support junior Application Security Engineers, promoting knowledge sharing and best practices;
  • Drive continuous improvement of the Secure Software Development Lifecycle (S-SDLC) framework;
  • Provide expert-level guidance to development teams on application security topics and secure development practices;
  • Lead vulnerability analysis, triage, remediation, and follow-up across applications and services;
  • Integrate security tools, including SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection, into CI/CD pipelines;
  • Lead security awareness initiatives, workshops, and developer training sessions;
  • Develop and maintain security documentation, standards, and best practice guidelines;
  • Define, monitor, and optimize security metrics, including KPIs, KRIs, and OKRs;
  • Conduct threat analysis and technological watch to identify emerging risks and security trends;
  • Propose and prototype innovative security solutions and improvements;
  • Support automation and continuous improvement of application security processes and tooling.

требования

  • Strong leadership skills with the ability to manage initiatives independently;
  • Excellent communication skills and the ability to explain technical topics to diverse audiences;
  • Strong teaching and mentoring abilities for developer enablement;
  • Analytical and structured problem-solving mindset;
  • Ability to influence and drive adoption of security practices across teams;
  • Strong documentation and technical writing skills;
  • Proactive, autonomous, and improvement-oriented mindset;
  • Strong expertise in application security tools and practices, including SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection;
  • Experience integrating security controls into CI/CD pipelines;
  • Strong programming skills in Python, C++, C#, or similar languages;
  • Solid understanding of OWASP Top 10 and common application vulnerabilities;
  • Experience in vulnerability analysis, remediation, and false-positive management;
  • Knowledge of cloud security across public, private, hybrid, and regulated environments;
  • Familiarity with development frameworks such as Angular, Hadoop, or similar;
  • Understanding of secure SDLC and DevSecOps practices.

условия

  • No conditions specified

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.