Job Details

Information Security
Mid-level
Hybrid
Full time
May 2

Application Security Engineer

Application Security Engineer at cloud.ru. Experience from 3 to 6 years. Salary is discussed during the interview. Location: Moscow. Hybrid work format.

Interaction with DevOps within the framework of integrating secure development tools; Application security analysis (product testing using automated tools) (SAST/DAST/SCA, Container security, etc.); Provide teams with information about found vulnerabilities and assist in their remediation; Participation in the development of rules for automated tools (SAST/DAST, etc.). Participate in BugBounty support.

Knowledge and understanding of the principles of exploiting threats from OWASP Top 10, CWE Top 25 and protecting against them; Skills in working with SAST, DAST, SCA/OSA, ASOC, etc. tools; Understanding the principles of REST/gRPC API structure; Understanding the principles of K8S operation – operators, webhooks, reconciliation loop; Understanding the principles of building secure inter-service communication; Experience with containerization tools (Docker, K8S) and automated deployment; Basic knowledge of DevOps/DevSecOps fundamentals (system landscape, their purpose, tasks solved, general understanding of processes). Experience in analyzing source code and identifying vulnerabilities, at least in Go/Python.

Russia
go
OWASP
K8s
CWE
Python
API
DevSecOps
SCA
Docker
REST
DAST
DevOps
SAST
BugBounty
gRPC

Don't miss a single job

Subscribe to our Telegram channel

Subscribe

Similar jobs

Application Security Engineer (AppSec)

Application Security Engineer (AppSec) at YADRO. Remote work available. Experience: 3-6 years. Salary discussed during interview.

Y
YADRO

AI Security Engineer

AI Security Engineer at T-Bank. Moscow. Salary is negotiable. Development of traffic inspection logic between applications and LLM, research into AI agent behavior, testing and validation of controls.

Russia
Т
Т-Банк