
Application Security Engineer
Devexperts6 months ago
Sofia, BulgariaMid Level
Responsibilities
- Conduct security assessments of applications, APIs, and third-party services using code reviews, static and dynamic analysis, vulnerability scanning, and penetration testing.
- Identify, prioritize, track, and verify remediation of application and API security vulnerabilities.
- Collaborate with software development teams to implement secure coding practices, security controls, threat modeling, and vulnerability management throughout the software development lifecycle.
- Develop and maintain automated security testing tools, frameworks, and processes for CI/CD pipelines.
- Provide security guidance on application architecture, API security, encryption, authentication, access control, and session management.
- Participate in application-security incident response, investigations, and breach remediation.
- Support risk assessments and compliance with internal standards and external requirements including GDPR, PCI-DSS, and HIPAA.
- Create and deliver security training and awareness programs for developers.
- Stay current with security threats, vulnerabilities, and application-security trends.
Requirements
- Bachelor’s degree in Computer Science, Information Security, Software Engineering, or a related field.
- More than 3 years of hands-on application security experience securing web applications, APIs, and cloud-based environments.
- Proficiency with SAST, DAST, vulnerability scanners, and penetration testing tools.
- Knowledge of secure coding practices, OWASP, NIST, common vulnerabilities such as the OWASP Top 10, and mitigation strategies.
- Experience with manual and automated source-code analysis, code reviews, security testing, and debugging.
- Experience integrating security practices into CI/CD pipelines in DevOps or Agile development environments.
- Understanding of web application security, session management, access control, authentication mechanisms, networking, HTTP/HTTPS, web servers, TLS, and SSL.
- Proficiency in at least one programming language such as Python, Java, JavaScript, or Ruby, with the ability to read and understand code.
- Strong analytical, problem-solving, communication, and cross-functional collaboration skills.
- Preferred certifications include CEH, CSSLP, GWAPT, CASE, OSWE, or other relevant cybersecurity certifications.
- Preferred experience includes AWS, Azure, or GCP security; threat-modeling tools and techniques; CI/CD and DevSecOps; Docker and Kubernetes security; microservices; and tools such as SonarQube or Veracode.
Benefits
- Hybrid or remote work options and flexible working hours.
- 20 days of paid vacation and 5 fully paid additional wellness days.
- Premium medical insurance and a free MultiSport card.
- Modern office with equipment, gym, relaxation facilities, PlayStation, billiards, parking or public transport card, and free drinks and snacks.
- Teambuilding activities, corporate events, football club, speakers’ club, and access to external corporate events.
- Conference and professional-fair participation opportunities.
- English and local-language courses, unlimited self-learning platforms, certification opportunities, and a mentorship program.
- Referral bonuses for specific roles and paid leave for special events.