Application Security Engineer

Devexperts

Not Interested
Bookmark
Report This Job

profile Job Location:

Sofia - Bulgaria

profile Monthly Salary: Not Disclosed
Posted on: 11 hours ago
Vacancies: 1 Vacancy

Job Summary

We are looking for an Application Security Engineer to join the Information Security Team. 

The Application Security Engineer will work closely with software development teams product owners and stakeholders to design implement and maintain robust security practices throughout the software development lifecycle (SDLC). The Application Security Engineer will be responsible for identifying and mitigating security vulnerabilities within applications systems and APIs ensuring secure coding practices and helping to maintain compliance with relevant security standards such as OWASP Top 10 NIST and ISO/IEC 27001.

This role will play a crucial part in strengthening the organizations security posture promoting security best practices and ensuring the safety and integrity of the companys software applications.

We expect the Application Security Engineer to:

  • Conduct regular security assessments of applications including code reviews static/dynamic analysis and penetration testing.
  • Collaborate with development teams to design and implement security controls and integrate security into the software development lifecycle (SDLC).
  • Lead and participate in the identification and remediation of security vulnerabilities in applications APIs and third-party services.
  • Provide security guidance on secure coding practices threat modeling and vulnerability management to development teams.
  • Implement and enforce security best practices for secure coding API security and encryption across application architectures.
  • Stay up-to-date with the latest security threats vulnerabilities and trends applying relevant knowledge to mitigate risks in applications.
  • Develop and maintain automated security testing tools frameworks and processes for continuous security integration within CI/CD pipelines.
  • Support risk assessments and threat modeling for new and existing applications helping to prioritize security remediation efforts.
  • Participate in incident response activities related to application security providing expertise to investigate and remediate security breaches.
  • Create and deliver security training and awareness programs for developers to promote a culture of security within the development teams.
  • Support vulnerability management and remediation efforts tracking and verifying the resolution of identified issues.
  • Ensure compliance with internal security standards and external regulatory requirements (e.g. GDPR PCI-DSS HIPAA).
  • Collaborate with cross-functional teams including DevOps infrastructure and security operations to ensure a cohesive approach to application security.

Qualifications :

Required Skills and Experience:

  • Bachelors degree in Computer Science Information Security Software Engineering or a related field.
  • Over 3 years of hands-on experience in application security with a focus on securing web applications APIs and cloud-based environments.
  • Proficiency with application security tools such as static and dynamic analysis (SAST DAST) vulnerability scanners and penetration testing tools.
  • Knowledge of secure coding practices and frameworks (OWASP NIST etc.) and experience applying them to real-world software development.
  • Familiarity with common vulnerabilities (e.g. OWASP Top 10) and mitigation strategies.
  • Experience with source code analysis including manual and automated code reviews security testing and debugging.
  • Experience working in a DevOps or Agile development environment including integration of security practices into CI/CD pipelines.
  • Understanding of web application security including session management access control and authentication mechanisms.
  • Proficient in at least one programming language (e.g. Python Java JavaScript Ruby etc.) and ability to read and understand code.
  • Strong knowledge of networking concepts HTTP/HTTPS protocols web servers and security protocols (TLS SSL etc.).
  • Excellent problem-solving and analytical skills with the ability to think like an attacker and identify security weaknesses in applications.
  • Strong communication skills with the ability to collaborate effectively with technical and non-technical stakeholders.

Preferred Qualifications:

  • Certifications such as CEH CSSLP GWAPT CASE OSWE or other relevant cybersecurity certifications.
  • Experience with cloud platforms (AWS Azure GCP) and security best practices for cloud-native applications.
  • Familiarity with threat modeling techniques and tools (e.g. OWASP Threat Dragon Microsoft SDL).
  • Experience with CI/CD and DevSecOps processes and tools.
  • Knowledge of container security (Docker Kubernetes) and microservices architecture.
  • Experience with application security tools such as SonarQube or Veracode for static and dynamic analysis.

Additional Information :

Care for the employees is one of Devexperts core values. For the suggested position we offer a benefits package that will guarantee the comfort of our new teammate.

Flexibility benefits:

  • Possibility of hybrid/remote work mode
  • Flexible working hours.

Health and recreation benefits:

  • 20 days of paid vacation
  • 5 days of fully paid additional wellness days
  • Medical insurance premium package
  • Free MultiSport card.

Facility benefits:

  • Modern office with new equipment
  • Panoramic view of Vitosha mountain
  • PlayStation Billiard Relax zone and Gym
  • Parking space/public transport card
  • Free drinks and snacks.

Community benefits:

  • Teambuilding activities
  • Corporate parties
  • Football club
  • Speakers club
  • Free admission to corporate external events
  • Possibility of joining conferences and professional fairs.

Professional training benefits:

  • English language courses
  • Local language courses for foreign employees
  • Unlimited access to self-learning platforms
  • Certification opportunities
  • Mentorship Program.

Social benefits:

  • Referral bonuses for specific roles
  • Paid leave upon special events.

Remote Work :

No


Employment Type :

Full-time

We are looking for an Application Security Engineer to join the Information Security Team. The Application Security Engineer will work closely with software development teams product owners and stakeholders to design implement and maintain robust security practices throughout the software developmen...
View more view more

Key Skills

  • Children Activity
  • EAM
  • Engineering Support
  • Maintenance Engineering
  • Accident Investigation
  • Branding

About Company

dxFeed is the leading provider of data services for the Capital Markets industry, sourcing and storing direct market data feeds from a variety of exchanges and market participants around the world, having built one of the most comprehensive ticker plants, in addition to offering the b ... View more

View Profile View Profile