Senior/Staff Application Security Engineer

Nebius Group

United States

Remote

USD 140,000 - 210,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Competitive compensation
Career growth
Flexible work
International teams

Job summary

Nebius is seeking a Senior/Staff Application Security Engineer to safeguard our software products across Compute, VPC, and managed services. You will drive secure coding practices and threat modeling, and collaborate with engineering teams to embed security into the SDLC.

The role involves building ASPM at scale, automating SAST/SCA in CI/CD, and maintaining secure guidelines. A strong background in OWASP, hands-on testing, and knowledge of SAML/OIDC are essential for success.

Qualifications

  • 6+ years of experience in application security.
  • Experience with secure coding practices in Python, Go, Java, or JavaScript.
  • Hands-on security testing with Burp Suite, ZAP, Semgrep.
  • Understanding of authentication protocols like SAML or OIDC.
  • Experience in threat-modeling sessions.

Responsibilities

  • Build and maintain Application Security Posture Management (ASPM) at the Company scale.
  • Automate and support SAST, SCA tools as part of CI/CD pipelines.
  • Improve SAST, secrets detection rules and reduce false positives.
  • Identify, analyze, and remediate application security vulnerabilities.
  • Collaborate with development teams to integrate security into the SDLC.
  • Develop and maintain secure coding guidelines for development teams.
  • Conduct threat modeling and risk assessments for new and existing apps.
  • Provide tools that facilitate security work like threat modelling and detection.
  • Stay updated on threats and mitigations; serve as security SME.

Skills

OWASP Top 10
Threat modeling
Secure coding
Python
Go
Java
JavaScript
Burp Suite
ZAP
Semgrep

Tools

Burp Suite
ZAP
Semgrep

Job description

About Nebius:

Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.

Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.

Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

Application Security

The team is responsible for the security of Nebius's main public offerings :Compute, VPC, Managed K8s, Marketplace, Managed Soperator, and others. This includes building out the Secure SDLC, threat modeling, and vulnerability management platforms.

The Role

We are looking for an Senior/Staff Application Security Engineer who will ensure the security of our software by identifying and mitigating vulnerabilities, implementing best security practices, and collaborating with development teams. The ideal candidate will have a strong background in secure coding, threat modeling and building Secure SDLC.

What you will do
  • Build and maintain Application Security Posture Management (ASPM) at the Company scale.
  • Automate and support SAST, SCA tools, etc as part of CI/CD pipelines.
  • Improving SAST, secrets detection rules. Keeping false positive rate low.
  • Identify, analyze, and remediate application security vulnerabilities.
  • Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC).
  • Develop and maintain secure coding guidelines for development teams.
  • Conduct, run threat modeling and risk assessments for new and existing applications.
  • Provide development teams with instruments that facilitate security-related work like threat modelling, vulnerability detection, etc.
  • Stay updated on the latest security threats, vulnerabilities, and mitigation techniques.
  • Serve as an application security subject matter expert to other teams.
What we look for
  • 6+ years of experience in application security.
  • Strong knowledge of common application security risks (e.g. OWASP Top 10) and how to mitigate them.
  • Experience with secure coding practices in languages such as Python, Go, Java, or JavaScript.
  • Proficiency in a common programming language (such as Go or Python) with a willingness to learn Go, if necessary.
  • Hands-on experience with security testing tools (Burp Suite, ZAP, Semgrep, etc.).
  • Understanding of authentication protocols like SAML or OIDC.
  • Experience in conducting threat-modeling sessions.
Bonus points
  • Confidence in presenting your ideas and opinions in a manner that can be challenged, while responding well to feedback.
  • Experience in designing, building, and maintaining security automation.
  • Experience in translating compliance and regulation requirements into technical specifications.
  • Experience in exploiting vulnerabilities in web applications, Linux kernels, containers, and networks.
  • Security certifications such as OSCP or OSWE.

We conduct coding interviews as part of the process.
#LI-CP1

  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams

What's it like to work at Nebius:

Fast moving- Bold thinking- Constant growth- Meaningful impact- Trust and real ownership- Opportunity to shape the future of AI

Equal Opportunity Statement:

Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.

Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.

If you need accommodations during the application process, please let us know.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations & Coordination Manager
Security Operations & Coordination Manager

Nebius Group • United States

On-site
USD 110,000 - 170,000
Competitive compensation
Career growth and learning
Flexibility and ownership
+3
Senior Software Engineer, Observability
Senior Software Engineer, Observability

Nebius • United States

On-site
USD 130,000 - 170,000
100% company-paid health insurance
401(k) match
Parental leave
+1
Project Manager — Cyber Security PMO
Project Manager — Cyber Security PMO

Nebius Group • City of Amsterdam (NY)

On-site
USD 103,000 - 148,000
Competitive compensation
Career growth and learning
International environment
+2
Senior Applied AI Solutions Engineer
Senior Applied AI Solutions Engineer

Nebius • Amsterdam (VA)

On-site
USD 200,000 - 350,000
Competitive compensation
Career growth
Flexible working arrangements
+3
Technical Program Manager (Post-Sales)
Technical Program Manager (Post-Sales)

Nebius Group • United States

Remote
USD 180,000 - 224,000
Health insurance
401(k) plan
Parental leave
+2
Technical Program Manager (Post-Sales)
Technical Program Manager (Post-Sales)

AI Chopping Block • Northern (KY)

On-site
USD 180,000 - 224,000
Health insurance
401(k) plan
Parental leave
+2
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Nebius Group • United States

On-site
USD 90,000 - 150,000
Competitive compensation
Career growth
Flexibility and ownership
+3
New AI and ISV Partner Business Development Manager
New AI and ISV Partner Business Development Manager

Nebius Group • San Francisco (CA)

On-site
USD 141,000 - 176,000
Health insurance
401(k) plan
Parental leave
+2
Forward Deployed Engineer, Ecosystem
Forward Deployed Engineer, Ecosystem

Nebius • United States

On-site
USD 208,800 - 261,000
Health Insurance
401(k) Plan
Parental Leave
+2
Frontend Engineer - User Interface
Frontend Engineer - User Interface

Nebius • United States

On-site
USD 122,880 - 184,320
Competitive compensation
Career growth and learning机会
Flexibility and ownership
+4