Application Security Engineer – Penetration Tester

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Growe Talents

Growe Talents

11 - 50 employees

💼 Consulting

📣 Marketing

🎯 Recruiter

Consulting • Marketing • Recruitment

Growe Talents is a recruitment agency specializing in the iGaming sector, focused on matching ambitious professionals with roles that drive both personal career growth and business performance. Born from the expert recruitment team at Growe, the company connects talent with opportunities across functions such as software development, CRM, marketing, content, and risk, and emphasizes meaningful matches based on skills, values, and growth potential. Growe Talents also promotes global opportunities, performance-driven rewards, and benefits aimed at supporting candidates and clients in a fast-paced, innovative industry.

📋 Description

• Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools; filter false positives, assess risks, and track issues through remediation • Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before production • Perform hands-on penetration testing of web applications, microservices, and APIs • Audit REST and GraphQL APIs and web applications, focusing on application security risks, authentication, authorization, and business logic

🎯 Requirements

• 3 years of experience in Application Security, Product Security, or Penetration Testing • Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner • Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec • Deep understanding of OWASP Top 10 vulnerabilities, including SQLi, Command Injection, SSRF, XSS, CSRF, IDOR/BOLA, security misconfigurations, cryptographic failures, insecure deserialization, and mass assignment • Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures • Deep understanding of OAuth 2.0, OIDC, JWT, SAML, and RBAC/ABAC • Ability to identify complex authorization bypasses, session management flaws, and business logic bugs • Ability to read and analyze modern application code to identify security flaws • Basic understanding of AWS cloud security principles and Kubernetes security fundamentals • Pragmatic approach to security and risk mitigation • Intermediate level of English, spoken and written • Strong communication skills for collaboration with engineering, product, and DevOps teams • Result-oriented mindset • Multitasking and time management skills

🏖️ Benefits

• Health & Wellness Focus • Global Medical Coverage • Growth Opportunities • Benefits Programs (compensation for the gym/stomatology/psychological service & etc.) • Performance-Driven Rewards • Dynamic Work Environment

Apply Now

Similar Jobs

🔥 4 hours ago

BJAK

51 - 200

🛍️ eCommerce

🛡️ Insurance

🏪 Marketplace

LLM Application Engineer building reliable AI assistants for A1, whose mission is intelligent support for conversations, errands, organisation, and workflows. Designing agent systems, integrating tools, and improving production AI quality.

Distributed Systems

Python

PyTorch

🕒 July 28

Nord Security

1001 - 5000

🔒 Cybersecurity

☁️ SaaS

🤝 B2B

Application Security Engineer ensuring security in mobile/desktop applications at NordVPN. Collaborating with cross-functional teams and supporting audits while managing security tools and reviews.

🇵🇱 Poland – Remote

💵 zł23k - zł30k / month

💰 $100M Private Equity Round - Nord Security on 2023-09

⏰ Full Time

🟠 Senior

💻 Application Engineer

Android

iOS

Linux

MacOS

TCP/IP

🕒 July 27

XTB online investing

1001 - 5000

💳 Fintech

💸 Finance

👥 B2C

Experienced SAP Consultant supporting SAP implementation and long-term maintenance at XTB, a leading global financial trading company in Poland.

🇵🇱 Poland – Remote

💰 $194.1M Post-IPO Secondary - Xtb on 2025-05

⏰ Full Time

🟡 Mid-level

🟠 Senior

💻 Application Engineer

🗣️🇵🇱 Polish Required

🕒 July 24

SOFTSWISS

1001 - 5000

💼 Consulting

📣 Marketing

🎮 Gaming

Security Application Security Engineer ensuring secure software throughout the SDLC for SOFTSWISS. Collaborating with product teams to identify and mitigate security vulnerabilities during development.

🗣️🇷🇺 Russian Required

🕒 April 1

WiPjobs Recruitment

11 - 50

💼 Consulting

📦 Logistics

📣 Marketing

Application Support Engineer involved in application layer implementation and monitoring server performance. Join a dynamic group in a flexible IT organization based in Poland.

Python

SQL