application security engineer in fintech
генерация резюме под вакансию
сопроводительное письмо
описание
Devexperts consults and develops software for the financial industry, solving complex technological challenges for financial institutions worldwide. The company creates financial software solutions and focuses on innovation and education.
задачи
- Conduct regular security assessments of applications, including code reviews, static and dynamic analysis, and penetration testing;
- Collaborate with development teams to design and implement security controls and integrate security into the software development lifecycle;
- Lead and participate in identifying and remediating security vulnerabilities in applications, APIs, and third-party services;
- Provide security guidance on secure coding practices, threat modeling, and vulnerability management;
- Implement and enforce secure coding, API security, and encryption best practices across application architectures;
- Monitor the latest security threats, vulnerabilities, and trends and apply relevant knowledge to mitigate application risks;
- Develop and maintain automated security testing tools, frameworks, and processes for continuous security integration within CI/CD pipelines;
- Support risk assessments and threat modeling for new and existing applications and help prioritize remediation efforts;
- Participate in application security incident response activities and investigate and remediate security breaches;
- Create and deliver security training and awareness programs for developers;
- Support vulnerability management and remediation efforts by tracking and verifying issue resolution;
- Ensure compliance with internal security standards and external regulatory requirements, including GDPR, PCI-DSS, and HIPAA;
- Collaborate with DevOps, infrastructure, and security operations teams on application security.
требования
- Bachelor’s degree in Computer Science, Information Security, Software Engineering, or a related field;
- Over 3 years of hands-on application security experience focused on web applications, APIs, and cloud-based environments;
- Proficiency with SAST, DAST, vulnerability scanners, and penetration testing tools;
- Knowledge of secure coding practices and frameworks such as OWASP and NIST;
- Familiarity with common vulnerabilities, including OWASP Top 10, and mitigation strategies;
- Experience with source code analysis, manual and automated code reviews, security testing, and debugging;
- Experience in DevOps or Agile development environments and integrating security practices into CI/CD pipelines;
- Understanding of web application security, including session management, access control, and authentication mechanisms;
- Proficiency in at least one programming language, such as Python, Java, JavaScript, or Ruby, and ability to read and understand code;
- Strong knowledge of networking concepts, HTTP/HTTPS, web servers, and security protocols such as TLS and SSL;
- Excellent problem-solving and analytical skills, with the ability to think like an attacker and identify application security weaknesses;
- Strong communication skills and ability to collaborate with technical and non-technical stakeholders;
- Nice to have: CEH, CSSLP, GWAPT, CASE, OSWE, or other relevant cybersecurity certifications, experience with AWS, Azure, or GCP, cloud-native application security, threat modeling techniques and tools, CI/CD and DevSecOps processes and tools, container security, Docker, Kubernetes, microservices architecture, SonarQube, Veracode.
условия
- Hybrid or remote work mode is available in Georgia;
- Flexible working hours;
- 24 Working days of paid vacation;
- Three fully paid additional wellness days per year;
- FitPass access;
- VIP medical insurance;
- Modern office with new equipment;
- Meals, free drinks, and snacks in the office;
- Teambuilding activities, corporate parties, football club, billiard club, and speakers’ club;
- Free admission to corporate external events;
- Access to conferences and professional fairs;
- Personal branding development support;
- Georgian language courses for foreign employees;
- Unlimited access to self-learning platforms;
- Certification opportunities;
- Mentorship Program;
- Parental bonus, referral bonus, paid leave for blood donation, and gifts for employees and children.
навыки
Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.