Application Security Engineer
Atomicwork Inc7 months ago
Bengaluru, IndiaMid Level
Responsibilities
- Develop and improve tools and processes for discovering and aggregating security vulnerabilities.
- Perform manual and automated assessments of Atomicwork applications.
- Build repeatable and automated security test suites.
- Conduct security-focused code reviews.
- Analyze system services and identify issues in code, networks, and applications.
- Integrate and automate SAST in the DevOps pipeline.
- Support the bug bounty program.
Requirements
- Familiarity with common security flaws, including the OWASP Top 10, and their remediation.
- Experience identifying security issues through code review.
- Proficiency in at least one of GitHub Actions, Argo CD, or Jenkins.
- Proficiency in Java or Python.
- Familiarity with security libraries and tools, including static analysis and proxying or penetration-testing tools.
- Good understanding of TCP, TLS, HTTPS, and DNS.
- Knowledge of vulnerabilities including cross-site scripting, SQL injection, CSRF, cryptographic weaknesses, and code injection.
- Ability to work effectively in a fast-paced environment.
- Preferred: proficiency in Kubernetes, AWS, and Linux.
- Preferred: understanding of REST architecture, SQL databases, and non-SQL databases.
Benefits
- Hybrid position based out of the Bengaluru office.
- Flexible work timings.
- Unlimited sick leave and 24 days off annually.
- Comprehensive health insurance for the employee's family.
- Premium Apple hardware.
- Flexible allowances and reimbursements.
- Team events and annual outings.