Senior/Staff Application Security Engineer

Nebius B.V.

Deutschland

Remote

EUR 90.000 - 130.000

Vollzeit

Vor 7 Tagen
Sei unter den ersten Bewerbenden

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

Nebius B.V. is seeking a Senior/Staff Application Security Engineer to secure software across the SDLC. You will drive ASPM at scale, automate SAST/SCA in CI/CD, and reduce false positives while integrating security into development teams.

The role emphasizes threat modeling, secure coding guidelines, and staying ahead of threats with hands-on experience in modern security tooling and protocols (SAML/OIDC). Your expertise will guide multiple teams in implementing robust security practices.

Qualifikationen

  • 6+ years of experience in application security.
  • Strong knowledge of common application security risks (e.g. OWASP Top 10) and how to mitigate them.
  • Experience with secure coding practices in languages such as Python, Go, Java, or JavaScript.
  • Hands-on experience with security testing tools (Burp Suite, ZAP, Semgrep, etc.).
  • Understanding of authentication protocols like SAML or OIDC.
  • Experience in threat-modeling sessions.
  • Experience in designing, building, and maintaining security automation.
  • Experience in translating compliance and regulation requirements into technical specifications.
  • Experience in exploiting vulnerabilities in web applications, Linux kernels, containers, and networks.
  • Security certifications such as OSCP or OSWE.

Aufgaben

  • Build and maintain Application Security Posture Management (ASPM) at the Company scale.
  • Automate and support SAST, SCA tools, etc as part of CI/CD pipelines.
  • Improving SAST, secrets detection rules.
  • Keeping false positive rate low.
  • Identify, analyze, and remediate application security vulnerabilities.
  • Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC).
  • Develop and maintain secure coding guidelines for development teams.
  • Conduct threat modeling and risk assessments for new and existing applications.
  • Provide development teams with instruments that facilitate security-related work like threat modelling, vulnerability detection, etc.
  • Stay updated on the latest security threats, vulnerabilities, and mitigation techniques.
  • Serve as an application security subject matter expert to other teams.

Kenntnisse

Application security
OWASP Top 10
Threat modelling
Python
Go
Java
JavaScript
Security automation
OSCP
OSWE

Tools

Burp Suite
ZAP
Semgrep

Jobbeschreibung

We are looking for a Senior/Staff Application Security Engineer who will ensure the security of our software by identifying and mitigating vulnerabilities, implementing best security practices, and collaborating with development teams. The ideal candidate will have a strong background in secure coding, threat modeling and building Secure SDLC.

What you will do
  • Build and maintain Application Security Posture Management (ASPM) at the Company scale.
  • Automate and support SAST, SCA tools, etc as part of CI/CD pipelines.
  • Improving SAST, secrets detection rules.
  • Keeping false positive rate low.
  • Identify, analyze, and remediate application security vulnerabilities.
  • Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC).
  • Develop and maintain secure coding guidelines for development teams.
  • Conduct, run threat modeling and risk assessments for new and existing applications.
  • Provide development teams with instruments that facilitate security-related work like threat modelling, vulnerability detection, etc.
  • Stay updated on the latest security threats, vulnerabilities, and mitigation techniques.
  • Serve as an application security subject matter expert to other teams.
What we look for
  • 6+ years of experience in application security.
  • Strong knowledge of common application security risks (e.g. OWASP Top 10) and how to mitigate them.
  • Experience with secure coding practices in languages such as Python, Go, Java, or JavaScript.
  • Proficiency in a common programming language (such as Go or Python) with a willingness to learn Go, if necessary.
  • Hands-on experience with security testing tools (Burp Suite, ZAP, Semgrep, etc.).
  • Understanding of authentication protocols like SAML or OIDC.
  • Experience in conducting threat-modeling sessions.
  • Bonus points Confidence in presenting your ideas and opinions in a manner that can be challenged, while responding well to feedback.
  • Experience in designing, building, and maintaining security automation.
  • Experience in translating compliance and regulation requirements into technical specifications.
  • Experience in exploiting vulnerabilities in web applications, Linux kernels, containers, and networks.
  • Security certifications such as OSCP or OSWE.
  • We conduct coding interviews as part of the process.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Application Security Engineer (all genders)
Application Security Engineer (all genders)

ABOUT YOU SE & Co. KG • Berlin

Vor Ort
EUR 65.000 - 75.000
Application Security & VIPR Expert
Application Security & VIPR Expert

Armis • Deutschland

Vor Ort
EUR 120.000 - 160.000
Senior Application Security Engineer
Senior Application Security Engineer

Zoomcar • Frankfurt

Vor Ort
EUR 70.000 - 90.000
(1111723) Senior Application Security Engineer
(1111723) Senior Application Security Engineer

Diversified Services Network, Inc. • Deutschland

Hybrid
EUR 86.000 - 116.000
401(k)
Dental insurance
Vision Insurance
+7
Senior SecOps Engineer
Senior SecOps Engineer

EPAM Systems • Deutschland

Hybrid
EUR 75.000 - 90.000
Senior Application Security Engineer
Senior Application Security Engineer

upstart • Deutschland

Hybrid
EUR 144.000 - 199.000
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Riederich

Vor Ort
EUR 80.000 - 120.000
Application Security Developer – AppSec - Berlin – €90,000–100,000
Application Security Developer – AppSec - Berlin – €90,000–100,000

Findr • Berlin

Vor Ort
EUR 90.000 - 100.000
Real influence on product security
Freedom to innovate
Supportive leadership
+1
Senior Security Consultant, Application Security
Senior Security Consultant, Application Security

IOActive, Inc. • Deutschland

Hybrid
EUR 70.000 - 150.000
Remote work flexibility
Travel opportunities
Competitive compensation
Associate Security Consultant
Associate Security Consultant

IOActive, Inc. • Deutschland

Hybrid
EUR 40.000 - 50.000
Remote work
Travel opportunities
Competitive compensation