Перейти к основному содержимому
Growe

Application Security Engineer / Penetration tester

УдалённоНе указано
Опубликовано
Роль
Безопасность
Опыт
Мидл
Зарплата не указана
Проверьте доступность

В объявлении не сказано, откуда нанимают. Проверьте описание или сайт работодателя перед откликом.

Коротко по делу

Application Security Engineer/Penetration Tester with 2-4 years of experience. Must have hands-on experience with SAST, SCA, and secret scanning tools (Semgrep, Gitleaks, Trivy, OSV-Scanner), and penetration testing tools (Burp Suite, Nuclei, Subfinder, SQLmap, Metasploit, NetExec). Requires deep understanding of OWASP Top 10, API security, and identity protocols. Intermediate English is required.

Ключевые навыки

Application SecurityPenetration TestingAPI Security

Обязательные навыки

SemgrepOpenGrepGitleaksTrivyOSV-ScannerBurp Suite ProNucleiSubfinderSQLmapMetasploitNetExecOWASP Top 10OWASP API Security Top 10OAuth 2.0OIDCJWTSAMLRBACABAC

Желательные навыки

modern application code analysisAWS securityKubernetes security

Обязательные языки

English Intermediate

Чем предстоит заниматься

  • Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation
  • Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production
  • Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws
  • Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorization, and business logic

Что требуется

  • 2-4 years of experience in Application Security, Product Security, or Penetration Testing
  • Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner
  • Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec
  • Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment
  • Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures
  • Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC)
  • Ability to identify complex authorization bypasses, session management flaws, and business logic bugs
  • Ability to read and analyze modern application code to spot security flaws (will be a plus)
  • Understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals (will be a plus)

Преимущества

  • Strong communication skills to effectively collaborate with engineering, product, and DevOps teams
  • Result-oriented mindset
  • Openness to learning
  • GROWE TOGETHER: Our team is our main asset. We work together and support each other to achieve our common goals
  • DRIVE RESULT OVER PROCESS: We set ambitious, clear, measurable goals in line with our strategy and driving Growe to success
  • BE READY FOR CHANGE: We see challenges as opportunities to grow and evolve. We adapt today to win tomorrow.

Growe is a leading business advisory and services group in iGaming and Entertainment. Сreators of strategies that work and solutions that scale. Combining strategic vision with hands-on expertise, Growe helps businesses navigate the fast-evolving industry, seize new opportunities, enter new markets, and achieve sustainable growth.

IGaming

Что говорят о компании

3.0/ 5

Зарплата не указана