Перейти к основному содержимому
Growe

Application Security Engineer / Penetration tester

УдалённоНе указано
Опубликовано
Роль
Безопасность
Опыт
Синьор
Зарплата не указана
Проверьте доступность

В объявлении не сказано, откуда нанимают. Проверьте описание или сайт работодателя перед откликом.

Коротко по делу

Application Security Engineer/Penetration Tester with 3+ years of experience. Must have hands-on experience with SAST, SCA, and secret scanning tools (Semgrep, Gitleaks, Trivy, OSV-Scanner), penetration testing tools (Burp Suite, Nuclei, SQLmap), and a deep understanding of OWASP Top 10 and API Security. Intermediate English required.

Ключевые навыки

Application SecurityPenetration TestingAPI Security

Обязательные навыки

SemgrepOpenGrepGitleaksTrivyOSV-ScannerBurp Suite ProNucleiSubfinderSQLmapMetasploitNetExecOWASP Top 10OWASP API Security Top 10OAuth 2.0OIDCJWTSAMLRBACABAC

Желательные навыки

modern application code analysiscloud security principles in AWS environmentsKubernetes security fundamentals

Обязательные языки

English Intermediate

Чем предстоит заниматься

  • Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation
  • Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production
  • Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws
  • Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorization, and business logic

Что требуется

  • 3 years of experience in Application Security, Product Security, or Penetration Testing
  • Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner
  • Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec
  • Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment
  • Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures
  • Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC)
  • Ability to identify complex authorization bypasses, session management flaws, and business logic bugs
  • Ability to read and analyze modern application code to spot security flaws (will be a plus)
  • Basic understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals (will be a plus)
  • Intermediate level of English (spoken and written)
  • Strong communication skills to effectively collaborate with engineering, product, and DevOps teams
  • Result-oriented mindset
  • Openness to learning

Преимущества

  • Health & Wellness Focus
  • Global Medical Coverage
  • Growth Opportunities
  • Benefits Programs (compensation for the gym/stomatology/psychological service & etc.)
  • Performance-Driven Rewards
  • Dynamic Work Environment

Growe is a leading business advisory and services group in iGaming and Entertainment. Сreators of strategies that work and solutions that scale. Combining strategic vision with hands-on expertise, Growe helps businesses navigate the fast-evolving industry, seize new opportunities, enter new markets, and achieve sustainable growth.

IGaming

Что говорят о компании

3.0/ 5

Зарплата не указана