Jobiglo

No results.

This job is no longer available

This job expired on 27/07/2026. It no longer accepts applications.

Application Security Engineer

Jobgether

Remote
Remote 🇬🇧 English
Burp Suite SonarQube Snyk SAST DAST CI/CD pipelines Secure coding practices OWASP Top 10 Penetration testing Threat modeling

Job description

About the role

This position sits at the intersection of software engineering and cybersecurity, focusing on strengthening the security posture of modern web and API‑based applications. You will work closely with engineering, product, and security teams in a remote‑first, fast‑moving environment to identify, validate, and remediate vulnerabilities.

Key responsibilities

  • Own and manage bug bounty intake, triage reports, validate vulnerabilities and reproduce proofs of concept.
  • Collaborate with developers and product owners to design and implement remediation strategies.
  • Review code and submit pull requests to fix security issues.
  • Support validation of external penetration testing results and integrate findings into development backlogs.
  • Participate in threat modeling, secure architecture discussions and security‑focused code reviews.
  • Enhance Secure Development Lifecycle practices, including SAST/DAST integration and automation in CI/CD pipelines.
  • Perform lightweight penetration testing on new features when required.
  • Maintain clear documentation of application security processes and best practices.

Required profile

  • Previous experience as a software developer or application security engineer in modern web or backend environments.
  • Hands‑on experience with security testing through bug bounty programs, CTFs or penetration testing.
  • Strong understanding of common application security vulnerabilities (e.g., OWASP Top 10).
  • Experience working closely with engineering and product teams in Agile settings.
  • Ability to analyze, reproduce and resolve complex security issues with a “find and fix” mindset.

Required skills

  • Bug bounty triage and validation
  • Burp Suite
  • SonarQube
  • Snyk
  • SAST and DAST tools
  • CI/CD pipeline integration
  • Secure coding practices for web and API applications
  • OWASP Top 10 knowledge
  • Penetration testing
  • Threat modeling

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Jobgether.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 4 months ago

24 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Jobgether