Application Security Engineer

Job not on LinkedIn

🕒 3 days ago

🇷🇸 Serbia – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

💻 Application Engineer

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of CCBill

CCBill

201 - 500 employees

Founded 1998

💼 Consulting

📦 Logistics

📣 Marketing

Consulting • Logistics • Marketing

CCBill is a leader in online payment processing services, offering comprehensive solutions for merchants around the globe. Founded in 1998, CCBill has established itself as a trusted provider for secure transactions, catering to over 30,000 internet businesses daily. The company's services include an advanced subscription and billing automation platform, fraud protection, and 24/7 customer support. CCBill supports various industries including eCommerce, high-risk businesses, adult content, dating, live cams, and more, ensuring seamless payment processing and consumer trust. With a focus on innovation, CCBill provides tools for billing and invoicing, as well as resources for eCommerce expansion and merchant growth.

📋 Description

• Perform manual and automated security assessments of web applications and APIs • Conduct application penetration testing to identify vulnerabilities, security weaknesses and configuration issues • Document findings, remediation recommendations and risk ratings in clear technical reports • Validate remediation activities through re-testing • Participate in threat modelling exercises and security design reviews • Perform security-focused source code reviews of internally developed applications • Support developers in understanding and remediating identified vulnerabilities • Promote secure coding practices and security awareness across development teams • Support the implementation and operation of security testing within CI/CD pipelines • Assist with deployment and tuning of SAST, DAST, SCA and secrets detection controls • Contribute to security automation initiatives using Jenkins, GitLab and Bitbucket • Track and manage vulnerabilities identified during security testing activities • Work with development teams to prioritise and remediate findings • Assess application security risks and recommend appropriate mitigation measures • Collaborate with development, architecture, infrastructure, and Information Security teams • Support security reviews prior to production deployments • Contribute to continuous improvement of application security standards, processes and procedures

🎯 Requirements

• Minimum 3 years of experience in application security, penetration testing, software development or a related information security role • Experience performing web application security assessments and penetration testing • Understanding of secure software development practices • Experience reviewing source code and identifying common security vulnerabilities • Strong knowledge of OWASP Top 10, CWE, NIST security guidance, and secure coding principles • Knowledge of web technologies, APIs, databases and networking concepts • Familiarity with Java, .NET/C#, Python, JavaScript, or Perl • Understanding of authentication, authorisation and session management concepts • Experience with tools such as Burp Suite, OWASP ZAP, Nessus, Metasploit, Wireshark, SAST and DAST tools • Exposure to Jenkins, GitLab, Bitbucket, and Agile development environments • Strong analytical and problem-solving skills • Effective verbal and written communication skills • Ability to work collaboratively within cross-functional teams • Proactive, strategic thinker who can turn concepts into actionable plans • Advocates security improvement initiatives while understanding business priorities and constraints • Demonstrated experience in mentoring, coaching, and supporting the growth of a diverse and distributed team

🏖️ Benefits

• Fully remote work arrangement • Monday to Friday, 40-hour workweek • Working hours from 1PM–9PM CET • Opportunity to learn and develop expertise in application security and DevSecOps practices

Apply Now