Application Security Engineer
A digital bank is seeking a hands-on Application Security Engineer to embed security across the software development lifecycle and help deliver secure web, mobile, API, and AI-enabled products.
Обязанности
- Embed security into the SDLC and SSDLC in partnership with development teams.
- Perform application security reviews, threat modeling, and security assessments.
- Identify vulnerabilities across web, Android, iOS, APIs, CI/CD pipelines, and software supply chains.
- Analyze business-logic flaws, authorization issues, insecure workflows, and abuse scenarios.
- Support developers with vulnerability remediation and secure solution design.
- Improve and automate security controls throughout the development lifecycle.
- Build internal tools for security testing, detection, and prevention.
- Develop and integrate AI-powered security solutions, including LLM-based tools, agents, and automated code and security analysis.
Требования
- 3–5 years of experience in application security, product security, security engineering, or software development with strong security experience.
- Strong software development knowledge and the ability to read and understand code.
- Hands-on web application security and native Android and iOS security experience.
- Knowledge of OWASP, OWASP Mobile, API security, authentication, authorization, and secure coding.
- Experience with CI/CD security, SAST, DAST, SCA, secrets management, and dependency risks.
- Ability to assess technical vulnerabilities and business-logic security risks.
- Development or scripting experience with Python, Java, Kotlin, JavaScript/TypeScript, or similar languages.
- Familiarity with AI and LLM technologies, including building security-focused tools or automations.
Будет плюсом
- Previous software development experience.
- Kotlin or Swift experience.
- Mobile application internals and mobile security testing experience.
- Experience with cloud, Kubernetes, containers, or infrastructure as code.
- Experience with LLM APIs, AI agents, retrieval-augmented generation, or AI-assisted code analysis.
- Knowledge of AI security risks, including prompt injection, data leakage, and excessive permissions.