14 авг

security engineer for web applications

ориентир по рынку
вакансия зп не указана
в среднем 343 365 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Wizeline is a global AI-native technology solutions provider that develops AI-powered digital products and platforms. It partners with clients to leverage data and AI, accelerate market entry, and drive business transformation.

задачи

  • Perform SAST, DAST, SCA, red team exercises, penetration testing, and manual code reviews on live applications and APIs;
  • Prioritize risks using CVSS and business context, and execute code-level patches and infrastructure configuration fixes across .NET, Java, and React stacks;
  • Configure, manage, and optimize enterprise security scanners, including Wiz, Snyk, Qualys, Burp Suite Enterprise/Pro, and OWASP ZAP;
  • Embed automated SAST/SCA scanning, dynamic secret management, and compliance gates into GitHub Actions CI/CD pipelines;
  • Conduct architecture security reviews and threat modeling based on OWASP SAMM principles;
  • Secure and harden hybrid architecture spanning AWS cloud environments, containerized workloads, and on-premise infrastructure;
  • Leverage AI tools to optimize and augment day-to-day work, provide recommendations on effective AI use, and identify opportunities to streamline workflows.

требования

  • Proven expertise in penetration testing, red teaming, manual code reviews, and dynamic analysis using tools such as Burp Suite Professional and OWASP ZAP;
  • Hands-on experience configuring and operating Wiz, Snyk, Qualys, SonarQube, and automated DAST platforms;
  • Ability to read, refactor, and patch vulnerable code across .NET, Java, and React stacks to remediate OWASP Top 10 vulnerabilities;
  • Experience embedding security into GitHub Actions pipelines and implementing dynamic secrets management with AWS KMS, HashiCorp Vault, and IAM;
  • Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and SBOM tracking;
  • Demonstrated track record securing AWS cloud environments, IAM policies, network controls, and hybrid/on-prem infrastructure;
  • Nice to have: OSCP, OSWE, CISSP, GWAPT, or AWS Certified Security – Specialty; familiarity with HIPAA, HITRUST, and PCI-DSS in healthcare or fintech environments; experience securing legacy monolithic architectures without operational downtime; experience securing Docker and Kubernetes/EKS ecosystems and runtime security monitoring; familiarity with AWS, GCP, Docker, Git, and secure API integration.

условия

  • Commitment to professional development;
  • Flexible and collaborative culture;
  • Global opportunities;
  • Vibrant community;
  • Total Rewards;
  • Specific benefits are determined by the employment type and location.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.