N-iXis a software development service company that helps businesses across the globe develop successful software products. Founded in 2002 in Lviv N-iX has come a long way and increased its presence in nine countries - Poland Ukraine Sweden Romania Bulgaria Malta the UK the US and Colombia. Today we are a strong community of 2000 professionals and a reliable partner for global industry leaders and Fortune 500 companies.
We are looking for an experienced Application Security Engineer to join our clients project. The Global Software Organization handles delivering standard software products to support a wide range of conveyor and sortation solutions warehouse automation and distribution operations. Development teams are distributed across multiple locations in North America and Europe. The Application Security Engineer will be participating in building the new application solutions reviewing the architecture and requirements for the existing applications reviewing the application development process and performing security testing of the applications or customer organizations.
Responsibility:
- Vulnerability Identification and Remediation: Conducting security assessments code reviews penetration testing and vulnerability scanning to identify and address security weaknesses in applications
- Security Standards and Best Practices: Establishing and enforcing security standards policies and procedures for application development
- Secure Development Lifecycle (SDLC) Integration: Working with development teams to integrate security practices into the SDLC from design to deployment
- Threat Modeling and Risk Assessment: Performing threat modeling and risk assessments to identify potential threats and vulnerabilities
- Security Tooling and Automation DevSecOps: Developing and implementing security tools frameworks and automation to enhance application security
Requirements :
- 4 years of experience in application security or other related areas
- 7 years of IT-related experience
- Knowledge of secure design principles
- Up-to-date knowledge of cybersecurity trends and industry
- Operational knowledge of modern operating systems and networking
- Experience with common cloud services: GCP is preferred; alternatively Azure and/or AWS
- Network Security basics and expertise in network pentesting
- Security testing of web applications web services mobile apps and IT infrastructure
- Ability to apply modern Application Security methodologies and frameworks
- Ability to use at least one modern programming language
- Practical experience with offensive security tooling (e.g. BurpSuite Nmap SQLMap etc.)
- Solid understanding of enterprise technologies and software development processes
- Understanding of security best practices tooling and common standards
- Fluent English
Personal Attributes:
- Quick starter and learner
- Readiness to learn new technologies and approaches
- Get things done attitude
- Strong interpersonal and oral communication skills (English)
- Ability to work in an unsupervised mode within scope and time constraints
Certifications:
- An offensive security certificate (e.g. OCSP) will be a big plus
- GCP certifications will be a big plus (e.g. Professional Cloud Developer or Professional Cloud Security Engineer)
We offer*:
- Flexible working format - remote office-based or flexible
- A competitive salary and good compensation package
- Personalized career growth
- Professional development tools (mentorship program tech talks and trainings centers of excellence and more)
- Active tech communities with regular knowledge sharing
- Education reimbursement
- Memorable anniversary presents
- Corporate events and team buildings
- Other location-specific benefits
*not applicable for freelancers
Required Experience:
Senior IC