Job Details

Information Security
Senior
Remote
Apr 22

Application Security Engineer

Application Security Engineer with 3+ years of experience. Salary discussed at interview. Company: UNIREST. Remote work.

• Implement and develop secure SDLC (SSDLC) processes at all stages of development. • Integrate and administer modern application security analysis tools (SAST, DAST, SCA, Secret Scanning, etc.) and ensure their operation in CI/CD. • Analyze scanning results, triage found vulnerabilities, coordinate and track their remediation. • Manage and develop WAF, analyze events, and ensure its integration with other security systems. • Provide consultations and training to teams on secure development, as well as code and architecture reviews. • Participate in Bug Bounty and pentests: analyze reports, confirm vulnerabilities, prepare infrastructure for checks. • Prepare analytical and technical reports, interact with internal and external teams.

• Deep understanding of SSDLC principles and experience in organizing and applying information security tools (WAF, SAST, DAST, SCA, etc.). • Skills in administering attack detection and prevention systems. • Experience in analyzing and interpreting scanning results, understanding vulnerabilities (OWASP) and methods for their remediation. • Excellent analytical skills, ability to work in a team and prepare clear reports. • Understanding of modern incident response methods. • Basic understanding of Python.

OWASP
Python
SCA
WAF
DAST
SAST
SSDLC

Don't miss a single job

Subscribe to our Telegram channel

Subscribe

Similar jobs

Application Security Engineer

Application Security Engineer at cloud.ru. Experience from 3 to 6 years. Salary is discussed during the interview. Location: Moscow. Hybrid work format.

Russia
c
cloud.ru

Application Security Engineer (AppSec)

Application Security Engineer (AppSec) at YADRO. Remote work available. Experience: 3-6 years. Salary discussed during interview.

Y
YADRO

AI Security Engineer

AI Security Engineer at T-Bank. Moscow. Salary is negotiable. Development of traffic inspection logic between applications and LLM, research into AI agent behavior, testing and validation of controls.

Russia
Т
Т-Банк