Devexperts

Application Security Engineer

Devexperts
Apply
6 months ago
Sofia, BulgariaMid Level

Responsibilities

  • Conduct security assessments of applications, APIs, and third-party services using code reviews, static and dynamic analysis, vulnerability scanning, and penetration testing.
  • Identify, prioritize, track, and verify remediation of application and API security vulnerabilities.
  • Collaborate with software development teams to implement secure coding practices, security controls, threat modeling, and vulnerability management throughout the software development lifecycle.
  • Develop and maintain automated security testing tools, frameworks, and processes for CI/CD pipelines.
  • Provide security guidance on application architecture, API security, encryption, authentication, access control, and session management.
  • Participate in application-security incident response, investigations, and breach remediation.
  • Support risk assessments and compliance with internal standards and external requirements including GDPR, PCI-DSS, and HIPAA.
  • Create and deliver security training and awareness programs for developers.
  • Stay current with security threats, vulnerabilities, and application-security trends.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Software Engineering, or a related field.
  • More than 3 years of hands-on application security experience securing web applications, APIs, and cloud-based environments.
  • Proficiency with SAST, DAST, vulnerability scanners, and penetration testing tools.
  • Knowledge of secure coding practices, OWASP, NIST, common vulnerabilities such as the OWASP Top 10, and mitigation strategies.
  • Experience with manual and automated source-code analysis, code reviews, security testing, and debugging.
  • Experience integrating security practices into CI/CD pipelines in DevOps or Agile development environments.
  • Understanding of web application security, session management, access control, authentication mechanisms, networking, HTTP/HTTPS, web servers, TLS, and SSL.
  • Proficiency in at least one programming language such as Python, Java, JavaScript, or Ruby, with the ability to read and understand code.
  • Strong analytical, problem-solving, communication, and cross-functional collaboration skills.
  • Preferred certifications include CEH, CSSLP, GWAPT, CASE, OSWE, or other relevant cybersecurity certifications.
  • Preferred experience includes AWS, Azure, or GCP security; threat-modeling tools and techniques; CI/CD and DevSecOps; Docker and Kubernetes security; microservices; and tools such as SonarQube or Veracode.

Benefits

  • Hybrid or remote work options and flexible working hours.
  • 20 days of paid vacation and 5 fully paid additional wellness days.
  • Premium medical insurance and a free MultiSport card.
  • Modern office with equipment, gym, relaxation facilities, PlayStation, billiards, parking or public transport card, and free drinks and snacks.
  • Teambuilding activities, corporate events, football club, speakers’ club, and access to external corporate events.
  • Conference and professional-fair participation opportunities.
  • English and local-language courses, unlimited self-learning platforms, certification opportunities, and a mentorship program.
  • Referral bonuses for specific roles and paid leave for special events.
Devexperts

About Devexperts

501-1,000 employees
Contact me