2 окт

product security engineer

ориентир по рынку
вакансия зп не указана
в среднем 219 880 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовься к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме

описание

Flexport provides technology that helps companies move goods around the world, making global commerce easier across 112 countries.

задачи

  • Build guardrails and AI-accelerated patterns that make secure-by-default the easiest path for developers
  • Build and maintain security tooling and automation that scales product security
  • Respond to emerging threats
  • Contribute pragmatic guidance to threat modeling, design reviews, and code reviews, balancing risk against velocity
  • Partner with engineering to review and test new features and services as they are built
  • Triage, reproduce, and validate bug bounty submissions and internal security reports
  • Prioritize real issues from SAST, secrets, and vulnerability scanner findings, and guide developers toward effective fixes
  • Partner with development teams to drive remediation and track issues through closure
  • Write actionable security patterns that help developers ship quickly and securely
  • Write and maintain runbooks, developer guidelines, and security documentation
  • Monitor web and cloud security trends and bring relevant findings into product discussions

требования

  • 2–5 Years of experience in product/application security or software development with a security focus
  • Strong understanding of web application security principles and common attack vectors, including OWASP Top 10
  • Proficiency with application testing tools such as Burp Suite, OWASP ZAP, or browser developer tools
  • Working knowledge of at least one modern programming language, such as Ruby, Java/Kotlin, TypeScript/JavaScript, or Python
  • Working knowledge of at least one major cloud provider: AWS, GCP, or Azure
  • Hands-on experience with SAST tools such as Cycode, Semgrep, Snyk, or similar
  • Experience improving developer experience (DevEx) security without slowing teams down
  • Clear, constructive communication of technical risk in writing, code reviews, and conversation
  • Collaborative approach with developers, SREs, and security peers
  • Comfortable with security on-call rotation and picking up work across security disciplines when needed
  • Будет плюсом: hands-on experience with bug bounty platforms, cloud infrastructure security and container technologies, participation in CTF events or open-source security projects, familiarity with threat modeling frameworks and secure SDLC best practices, interest in contributing to internal developer security training programs

условия

  • In Amsterdam, employees come to the office 3 times a week
  • Latest hardware and software, including frontier AI models on day one
  • Flexport covers home-office commuting costs for employees living outside Amsterdam
  • 25 Working days of vacation based on full-time employment
  • Collective health insurance, with the monthly premium fully paid by Flexport
  • Defined pension contribution scheme
  • Equity program; every team member becomes a shareholder
  • Employee Assistance Program through Aetna Resources for Living at no cost to employees and household members
  • Parental leave for mothers and partners
  • Daily catered lunches, including vegetarian options, breakfast, snacks, and soft drinks at the office

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.