Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
We are looking for a technically strong Senior Application Security practitioner ready to take on real ownership. You will work directly with the Head of AppSec, contributing to the Secure Design practice and helping drive shift-left security across the organization.
задачи
Build and mature the Secure Design and Threat Modeling program by defining methodology, review standards, and sign-off criteria across the organization
Drive shift-left security initiatives by embedding security earlier in the development lifecycle through design reviews, developer enablement, and security gating in CI/CD
Own API security as a discipline
Support offensive security initiatives
Build and maintain security automation in Python to scale AppSec capacity
Work directly with developers on SAST and SCA remediation, scan optimization, and reducing friction in the security feedback loop
Contribute to AI-assisted security pipelines and define escalation paths, SLAs, and accountability structures for vulnerability management
требования
Hands-on experience across secure design, threat modeling, API security, and offensive security
Penetration testing experience and a solid understanding of real-world attack and API exploitation patterns
Deep familiarity with OWASP Top 10 in practice
Experience assessing REST and GraphQL APIs
Proficiency in Python and ability to build automation tools others can depend on
Experience in shift-left programs, including security in CI/CD, developer enablement, and design review processes
Understanding of web application and API security
Ability to read code across languages and engage with engineering teams at technical depth
Familiarity with cloud-native environments and attack surface management
Ability to influence across engineering and product and operate at architecture level
Будет плюсом: OSCP, OSWE, GWEB, CSSLP, CISSP, or CEH certifications, exposure to AI-assisted security tooling or LLM security, experience as a developer, fluency in Ruby, Python, and Scala
условия
Employees in this role work in the office four days and remotely one day (Friday)
Competitive salary, annual performance bonus, and equity for full-time employees