Nebius

Senior/Staff Application Security Engineer

Nebius
Apply
3 days ago
Remote, EMEASenior / Staff+

Responsibilities

  • Build and maintain Application Security Posture Management at company scale.
  • Automate and support SAST, SCA, secrets detection, and related security tools in development pipelines.
  • Improve SAST and secrets-detection rules while maintaining a low false-positive rate.
  • Identify, analyze, and remediate application security vulnerabilities.
  • Integrate security best practices into development teams’ software development lifecycle.
  • Develop secure coding guidelines and tools for development teams.
  • Conduct threat-modeling sessions and risk assessments for applications.
  • Serve as an application security subject matter expert for other teams.

Requirements

  • 6+ years of experience in application security.
  • Strong knowledge of common application security risks, including the OWASP Top 10, and their mitigations.
  • Experience with secure coding in Python, Go, Java, or JavaScript.
  • Proficiency in a common programming language such as Go or Python, with willingness to learn Go if needed.
  • Hands-on experience with Burp Suite, ZAP, Semgrep, or similar security testing tools.
  • Understanding of authentication protocols such as SAML or OIDC.
  • Experience conducting threat-modeling sessions.
  • Preferred qualifications include security automation, compliance-to-technical-specification work, vulnerability exploitation, and OSCP or OSWE certifications.

Benefits

  • Competitive compensation.
  • Career growth and learning opportunities.
  • Flexibility and ownership.
  • Collaborative and innovative culture.
  • Opportunity to work on impactful AI projects.
  • International environment with talented teams.
Nebius

About Nebius

1,001-5,000 employees

The Nebius AI Cloud brings powerful full-stack infrastructure for AI developers and practitioners across startups, enterprises and science institutes to build and deploy generative AI applications and rapidly deliver scientific breakthroughs by training and running ML models within a secure, high-performance, and cost-optimized cloud environment.

Contact me