Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Applications for this job are no longer accepted.
Grid Dynamics provides technology consulting, platform and product engineering, AI, and advanced analytics services. The company helps enterprise organizations solve complex technology challenges and achieve business outcomes during digital transformation.
задачи
Own the end-to-end security capability roadmap, defining vulnerability coverage, detection frameworks, and competitive benchmarks against commercial and open-source tools;
Design, curate, and maintain the platform's benchmark corpus using seeded and labelled vulnerabilities across multiple programming languages;
Establish measurement methodologies to track detection performance, safeguard published metrics, and run standing evaluations against competing tools;
Adjudicate findings, define triage standards, and resolve complex false-positive or missed-detection reports;
Author multi-language test cases, manage vulnerability classification mappings such as CWE and OWASP, and continuously expand the regression corpus;
Perform security reviews of harness code changes and external contributions before merging;
Reproduce reported detection failures, document minimal test cases, and execute benchmark passes with every platform release.
требования
3+ Years of commercial experience in application security, security engineering, or vulnerability research;
Strong hands-on experience in secure code review and threat analysis across multiple programming languages, including Python, Java, Go, C/C++, and JavaScript/TypeScript;
Deep understanding of vulnerability classification frameworks, including CWE and OWASP Top 10, and root-cause analysis;
Proven track record in vulnerability triage, false-positive reduction, and developing reproducible test cases or PoCs;
Experience creating or managing security benchmark corpora, evaluation frameworks, or automated testing suites;
Solid grasp of modern security testing methodologies, static analysis (SAST), and dynamic evaluation techniques.
условия
Competitive salary;
Flexible schedule;
Benefits package including medical insurance and sports benefits;