Application Security Engineer

n11

Sarıyer

On-site

TRY 350,000 - 520,000

Full time

34 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

n11 is seeking an Application Security Engineer to join our Technology/Infrastructure Department. You will perform penetration testing, vulnerability assessments, and threat modeling across web apps, infrastructure, and cloud environments.

You will lead remediation efforts, collaborate with DevOps and product teams, and advance security in CI/CD pipelines. A strong bug bounty background and experience with OWASP standards are highly valued.

Qualifications

  • Bachelor's degree or equivalent practical experience.
  • 4+ years in computer tech field (IT, support, or engineering).
  • Proficient in at least one programming language (e.g., Java, Golang) and scripting (Bash/Python).
  • Hands-on experience with application security practices (SAST/DAST/SSA, threat modeling).
  • Experience in application penetration testing, vulnerability research, or bug bounty hunting.
  • Strong understanding of SSDLC and OWASP Top 10 vulnerabilities.

Responsibilities

  • Penetration testing of web apps, infrastructure, and cloud environments.
  • Vulnerability management and remediation in development and production.
  • Communicate findings and remediation steps to stakeholders.
  • Develop automation scripts to support security testing in CI/CD pipelines.
  • Oversee attack surface management and proactive security measures.
  • Collaborate with DevOps, QA, and product teams to embed security.

Skills

Java
Golang
Python
Bash

Education

Bachelor's degree in Computer Science or related field

Tools

OWASP
SAST
DAST
SCA
WAF

Job description

Get ready to take your place on n11, an open market platform has made valuable contributions to the e-commerce sector since its establishment by bringing more than 330 thousand registered business partners to customers.

We are looking for "Application Security Engineer” to join our team in Technology/Infrastructure Department.

Who you are
  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field - or equivalent practical experience.
  • 4+ years professional experience in a computer technology field including IT, technical support, or engineering
  • Proficient in coding with at least one programming language (e.g., Java, Golang) and scripting languages like Bash or Python.
  • Hands-on experience with application security practices including code review, threat modeling, static and dynamic analysis (SAST, DAST, SCA), and attack surface analysis.
  • Experience in Application Penetration Testing, Vulnerability Research, or Bug Bounty Hunting.
  • Strong understanding of the Secure Software Development Lifecycle (SSDLC), with a focus on shifting security left - embedding security into early development stages to identify and mitigate vulnerabilities before they reach production.
  • Deep familiarity with OWASP standards and best practices, particularly the OWASP Top 10 vulnerabilities, and experience applying them to secure web applications and services.
  • Experience with web security concepts such as secure authentication, session management, Server Side Request Forgery (SSRF), SQL injection, and other common web vulnerabilities.
  • Familiarity with mobile-specific security frameworks and tools (e.g., OWASP Mobile Top 10, MobSF, Frida) for testing and securing mobile apps.
  • Certifications in relevant security domains (e.g., OSWE, GWAPT, OSCP) are a plus.
  • Cloud and container security experience is a plus
  • A strong bug bounty profile with demonstrated experience in discovering and responsibly disclosing vulnerabilities is also a plus.
  • Proven ability to solve complex security challenges, develop risk-based solutions, and effectively balance security requirements with engineering goals, while influencing stakeholders with diverse perspectives on security.
What you'll do
  • Penetration Testing & Vulnerability Assessments: Test web apps, infrastructure, and cloud environments for vulnerabilities using manual and automated techniques. Develop custom tools and scripts to improve testing in CI/CD pipelines.
  • Vulnerability Management & Remediation: Work with teams to analyze vulnerabilities, create remediation plans, and enhance security in development and production using DAST, SAST, Internal Network Security and SCA tools.
  • Security Communication & Reporting: Present findings and remediation steps to both technical and non-technical stakeholders.
  • Automation Scripting: Collaborate with teams to understand security requirements and develop automation scripts that provide valuable security insights.
  • Attack Surface Management: Oversee and optimize the attack surface by analyzing logs, identifying vulnerabilities, and developing tools to enhance efficiency and improve proactive security measures. Focus on reducing exposure and strengthening overall defense mechanisms.
  • Collaboration with Cross-Functional Teams: Work closely with DevOps, QA, product management, and other departments to integrate security seamlessly into the development and deployment processes. Advocate for security as a shared responsibility across teams.
  • Continuous Improvement: Stay up-to-date with the latest trends, tools, and techniques in application security. Promote a culture of continuous improvement by identifying areas for further optimization and driving the adoption of best practices.
  • Utilizing WAF for Web Application Security: Leverage Web Application Firewalls (WAF) to protect applications by filtering malicious traffic, minimizing risks, and enhancing security through real-time threat detection, customized rule sets, and continuous monitoring
  • On-Call Rotation Alert/Incident Management and Darkweb/threat intelligence tracking .

As n11, we care about your Personal Data Security. Please find the Personal Data Protection Information Notice from the link below.

https://n11scdn.akamaized.net/custom/upload/51/79/2889579912657586679.pdf

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer: Threat Modeling & Testing
Application Security Engineer: Threat Modeling & Testing

n11 • Sarıyer

On-site
TRY 350,000 - 520,000
Senior Security Engineer - Crypto
Senior Security Engineer - Crypto

Stack Recruitment • Fatih

On-site
TRY 360,000 - 540,000
Research time for tooling and security
Career growth in technical security
AppSec - Vulnerability Management Engineer
AppSec - Vulnerability Management Engineer

Jobless • Fatih

On-site
TRY 180,000 - 280,000
Senior Infrastructure and Application Security Specialist
Senior Infrastructure and Application Security Specialist

Gizli • Fatih

On-site
TRY 300,000 - 500,000
Senior Information Security Specialist
Senior Information Security Specialist

Pazarama • Kartal

Hybrid
TRY 420,000 - 700,000
Information Security Specialist
Information Security Specialist

Aygaz • Fatih

On-site
TRY 450,000 - 650,000
Security Engineer
Security Engineer

Crs Soft • Fatih

On-site
TRY 400,000 - 640,000
Buffet breakfast
Education fund
Birthday off
+5
Mid - Senior Network Planning Engineer
Mid - Senior Network Planning Engineer

n11 • Sarıyer

On-site
TRY 300,000 - 540,000
Cyber Prevent Manager
Cyber Prevent Manager

Vodafone Group Plc • Fatih

On-site
TRY 3,263,000 - 5,595,000
Engineering Manager - Security Standards and Hardening
Engineering Manager - Security Standards and Hardening

Jobgether • Turkey

On-site
TRY 360,000 - 600,000
Annual bonus
Learning budget USD 2,000 per year
Travel opportunities
+1