Die ganze Ausschreibung von Nebius B.V.
Das ist der Job
The ideal candidate will have a strong background in secure coding, threat modeling and building Secure SDLC.
Darum lohnt es sich
We are looking for a Senior/Staff Application Security Engineer who will ensure the security of our software by identifying and mitigating vulnerabilities, implementing best security practices, and collaborating with development teams.
What you will do • Build and maintain Application Security Posture Management (ASPM) at the Company scale. • Automate and support SAST, SCA tools, etc as part of CI/CD pipelines. • Improving SAST, secrets detection rules. • Keeping false positive rate low. • Identify, analyze, and remediate application security vulnerabilities. • Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC). • Develop and maintain secure coding guidelines for development teams. • Conduct, run threat modeling and risk assessments for new and existing applications. • Provide development teams with instruments that facilitate security-related work like threat modelling, vulnerability detection, etc. • Stay updated on the latest security threats, vulnerabilities, and mitigation techniques. • Serve as an application security subject matter expert to other teams.
What we look for • 6+ years of experience in application security. • Strong knowledge of common application security risks (e.g.
OWASP Top 10) and how to mitigate them. • Experience with secure coding practices in languages such as Python, Go, Java, or JavaScript. • Proficiency in a common programming language (such as Go or Python) with a willingness to learn Go, if necessary. • Hands-on experience with security testing tools (Burp Suite, ZAP, Semgrep, etc.). • Understanding of authentication protocols like SAML or OIDC. • Experience in conducting threat-modeling sessions. • Bonus points Confidence in presenting your ideas and opinions in a manner that can be challenged, while responding well to feedback. • Experience in designing, building, and maintaining security automation. • Experience in translating compliance and regulation requirements into technical specifications. • Experience in exploiting vulnerabilities in web applications, Linux kernels, containers, and networks. • Security certifications such as OSCP or OSWE. • We conduct coding interviews as part of the process.
Bereit?
Bewerbung wird direkt an Nebius B.V. übergeben — kein Konto nötig.