Overview
Join to apply for the Senior Application Security Engineer role at BrainRocket.
We’re BrainRocket — an international software development and digital solutions company driven by 1,300 talented professionals across Cyprus, Malta, and Portugal. Here, everything moves at rocket speed: driving innovation, pioneering projects, and fast-tracking careers. Together, we turn ideas into action — let’s get started!
We invite a Senior Application Security Engineer to join our team remotely.
Responsibilities
- Demonstrated ability to collaborate with other teams to achieve complex objectives.
- Design security architecture from cloud infrastructure to applications, implementing “secure by design” principles.
- Collaborate with product managers, architects, and developers on the implementation of the security controls platform ecosystem and products.
- Prove security implementations within infrastructure and application deployment manifests and the CI/CD pipelines.
- Define required policies, controls, and capabilities for the protection of products and environments.
- Build and validate declarative threat model automation.
- Participate in engineering teams’ product planning cycles and committees.
- Oversee product security aspects for migration of products and services from data centers to the public cloud (e.g., AWS).
- Serve as a trusted cybersecurity advisor to product and application teams.
Qualifications
- Minimum of 3 years of experience as an Application Security Engineer.
- Experience integrating security scanning/tooling into the development pipeline.
- Experience with CI/CD pipelines (e.g., GitLab, Jenkins) and infrastructure-as-code models (Terraform, Helm, CloudFormation).
- Strong understanding of supply chain security, software integrity, and secure software delivery.
- Experience with Docker and mesh technologies (e.g., Istio).
- Experience with architecture and security reviews, threat modeling, and application risk (highly desirable).
- Experience working with Agile methodologies.
- Knowledge of privacy laws and regulations, such as GDPR (desired).
- Familiarity with industry regulations, frameworks, and practices (e.g., PCI, ISO 27001, NIST).
- In-depth experience with architecting secure services on Kubernetes.
- Extensive experience architecting secure services on AWS or on-premises data centers.
- Security-related certifications (e.g., CISSP, CISM, CCSK, CCSP, CEH) highly desirable.
Benefits
- Learning and development opportunities and interesting, challenging tasks.
- Opportunity to develop language skills, with partial compensation for English classes.
- Time for proper rest, with 20 working days of annual vacation.
- Competitive remuneration with annual reviews.
Additional details
- Seniority level: Mid-Senior level
- Employment type: Full-time
- Industries: Gambling Facilities and Casinos, Financial Services, and Computer Games