Devexperts
Application Security Engineer
Tbilisi, Tbilisi, Georgia
Sponsorship not specifiedDetected 133 days ago
JavaScriptPythonJavaRubyCode ReviewAWSGCPAzureCloud PlatformsDockerKubernetesCI/CDDevOpsCybersecurityPenetration TestingSOC OperationsIncident ResponseComplianceBrand StrategyHIPAACommunicationProblem SolvingMentoring
About the role
- We solve complex technological challenges facing the most well-respected financial institutions worldwide.
- We welcome all candidates who believe, as we do, that innovation is grounded in education.
- This role will play a crucial part in strengthening the organization's security posture, promoting security best practices, and ensuring the safety and integrity of the company's software applications.
Responsibilities
- Our teams work together to create the next generation of financial software solutions.
- The Application Security Engineer will work closely with software development teams, product owners, and stakeholders to design, implement, and maintain robust security practices throughout the software development lifecycle (SDLC).
- The Application Security Engineer will be responsible for identifying and mitigating security vulnerabilities within applications, systems, and APIs, ensuring secure coding practices, and helping to maintain compliance with relevant security standards such as OWASP Top 10, NIST, and ISO/IEC 27001.
- Personal branding development support.
Requirements
- Bachelor's degree in Computer Science, Information Security, Software Engineering, or a related field.
- Over 3 years of hands-on experience in application security, with a focus on securing web applications, APIs, and cloud-based environments.
- Proficiency with application security tools such as static and dynamic analysis (SAST, DAST), vulnerability scanners, and penetration testing tools.
- Knowledge of secure coding practices and frameworks (OWASP, NIST, etc.) and experience applying them to real-world software development.
- Familiarity with common vulnerabilities (e.g., OWASP Top 10) and mitigation strategies.
- Experience with source code analysis, including manual and automated code reviews, security testing, and debugging.
- Experience working in a DevOps or Agile development environment, including integration of security practices into CI/CD pipelines.
- Proficient in at least one programming language (e.g., Python, Java, JavaScript, Ruby, etc.) and ability to read and understand code.
- Strong knowledge of networking concepts, HTTP/HTTPS protocols, web servers, and security protocols (TLS, SSL, etc.).
- Excellent problem-solving and analytical skills, with the ability to think like an attacker and identify security weaknesses in applications.
Nice to have
- Certifications such as CEH, CSSLP, GWAPT, CASE, OSWE or other relevant cybersecurity certifications.
- Experience with cloud platforms (AWS, Azure, GCP) and security best practices for cloud-native applications.
- Familiarity with threat modeling techniques and tools (e.g., OWASP Threat Dragon, Microsoft SDL).
- Experience with CI/CD and DevSecOps processes and tools.
- Knowledge of container security (Docker, Kubernetes) and microservices architecture.
- Experience with application security tools such as SonarQube or Veracode for static and dynamic analysis.
- Care for the employees is one of dxFeed' core values.
- FitPass (sport and related activities) access,
Skills
- Conduct regular security assessments of applications, including code reviews, static/dynamic analysis, and penetration testing.
- Provide security guidance on secure coding practices, threat modeling, and vulnerability management to development teams.
- Ensure compliance with internal security standards and external regulatory requirements (e.g., GDPR, PCI-DSS, HIPAA).
Benefits
- Flexible working hours.
- Health and recreation
- 24 working days of paid vacation,
- Fully paid additional wellness days (3 days per year),
- Medical insurance - VIP package.
Company info
- Devexperts has been working for nearly two decades consulting and developing for the financial industry.
- By becoming a part of Devexperts, you'll become a part of a company that fosters self-improvement and actively seeks out-of-the-box ideas.
- We are looking for an Application Security Engineer to join the Information Security Team.
Apply directly at Devexperts →Create a free account for alerts like thisView Devexperts immigration profile
This listing is sourced directly from Devexperts's careers page and normalized into a canonical job model.