сегодня

security engineer for HR technology

ориентир по рынку
вакансия зп не указана
в среднем 328 556 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Tellent provides a Talent Management Suite that helps organizations attract, hire, manage, and grow their people. Its platform combines Applicant Tracking, HRIS, and Performance Management solutions used by 7,000+ companies across 100+ countries. The company builds scalable HR technology focused on employee experiences and protects sensitive candidate and employee information.

задачи

  • Perform deep manual security reviews and offensive testing across services, APIs, and clients, focusing on authorization, multi-tenancy, business logic, and other high-risk areas;
  • Threat model high-risk product surfaces, including new AI functionality, and help teams develop the skills to run this practice themselves;
  • Own the technical strategy for application security tooling, currently Aikido, with a focus on actionable signals, developer experience, and low false-positive rates;
  • Triage vulnerabilities from internal tooling, penetration tests, and external researchers, make defensible severity calls, and partner with teams to verify fixes;
  • Identify patterns and root causes across findings and build systemic fixes, secure-by-default libraries, and paved paths that prevent recurring vulnerabilities;
  • Develop secure development standards for engineers’ day-to-day work;
  • Partner with the Security team on the bug bounty programme, pentest remediation, security champions network, and training based on real findings;
  • Act as a senior technical partner for product security incidents and engineering controls required by security or privacy commitments;
  • Shape and own the product security roadmap across Backend, Frontend, QA, DevOps, Product, and Security;
  • Build a clear picture of the current threat landscape and deliver a prioritised assessment of key product security risks;
  • Establish threat models for the highest-risk surfaces and ship systemic improvements that remove classes of vulnerabilities;
  • Embed secure-by-default standards and paved paths into engineering workflows.

требования

  • Strong engineering foundation with deep hands-on application or product security experience across engineering and security roles;
  • Proven experience personally identifying vulnerabilities and explaining the full process from hypothesis and impact validation to remediation;
  • Strong understanding of access control, multi-tenancy, authentication and authorization, session management, injection vulnerabilities, SSRF, deserialization, business logic abuse, and supply-chain risk;
  • Comfortable reading and writing production code and reasoning about unfamiliar systems and technologies;
  • Experience threat modelling real systems and translating findings into practical engineering work;
  • Working knowledge of cloud security, containers, CI/CD, and infrastructure as code;
  • Technology-agnostic mindset with the ability to work across different languages, stacks, and environments;
  • Excellent communication skills for explaining subtle vulnerabilities and discussing trade-offs with senior stakeholders;
  • Collaborative, low-ego approach focused on enabling product teams and building early engagement;
  • Nice to have: AI and LLM application security, privacy engineering, OAuth 2.0, OIDC, SAML, offensive security, company or platform integrations, building a product security practice from an early stage, OSCP, CISSP, CISM, or CSSLP certifications.

условия

  • Hybrid or remote working setup across the Netherlands, Germany, and Poland;
  • Opportunity to establish and shape product security within the Engineering organisation from the ground up;
  • Significant autonomy and direct collaboration with the VP of Engineering and engineering leadership;
  • Diverse, multicultural, and remote-friendly environment;
  • €1,500 Annual training budget and 2 dedicated learning days;
  • Dedicated tooling budget and opportunities to attend conferences and conduct security research;
  • Pension plan, travel reimbursement, and wellness perks;
  • 28 Paid holiday days plus 2 additional days to relax;
  • Work from anywhere for 4 weeks per year;
  • Apple MacBook and top-tier tooling;
  • €200 Home office budget;
  • Benefits may differ based on employment location.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.