5 months ago
Remote, PolandMid Level
Responsibilities
- Partner with product teams on threat modeling and risk assessment during the design phase.
- Perform manual code reviews and white-box security assessments to identify logical vulnerabilities.
- Tune automated security scanning rulesets to reduce false positives and improve detection rates.
- Develop scripts and automation tools to streamline security workflows.
- Help developers understand and remediate risks identified through assessments, threat modeling, and dynamic testing.
- Triage bug bounty vulnerabilities and coordinate resolution with external researchers and internal engineering teams.
- Provide security consulting, knowledge sharing, and actionable guidance to development and QA teams.
- Maintain secure coding guidelines, technical manuals, and the internal security knowledge base.
Requirements
- At least 3 years of experience in application security, software development, or related technical roles.
- Solid understanding of HTTP/HTTPS, cookie storage mechanisms, and session management.
- Knowledge of web application security controls including SOP, CORS, and CSP.
- Comprehensive knowledge of common web vulnerabilities such as the OWASP Top 10 and their mitigation.
- Hands-on experience with manual security assessments and secure code reviews.
- Knowledge of secure system and application architecture and secure-by-design principles.
- Ability to explain the business impact of threats and vulnerabilities to technical and product stakeholders.
- University degree in Computer Science, Information Security, or a related field, or an equivalent combination of education and practical experience.
- Upper-intermediate English and Russian proficiency at B2+ level.
- Preferred qualifications include programming experience, network and operating systems security knowledge, DevSecOps experience, bug bounty or CTF participation, SAST/DAST customization experience, and certifications such as BSCP or eWPT.
Benefits
- Full-time remote work with flexible working hours.
- Private insurance, sports program compensation, and a comprehensive mental health program.
- One additional day off per calendar year.
- Free online English lessons with a native speaker.
- Generous referral program.
- Training, internal workshops, international professional conferences, and corporate events.
