application security engineer
ориентир по рынку
вакансия
зп не указана
в среднем
218 868 ₽
мэтч
Загрузи резюме, чтобы видеть мэтчи с вакансией
Загрузить
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
загрузить резюме
описание
Starburst delivers enterprise intelligence at scale by providing secure, governed access to data wherever it resides. Built for distributed data environments, Starburst supports AI and analytics with open standards including Trino and Apache Iceberg, helping enterprises avoid the cost, complexity, and vendor lock-in of traditional data consolidation.
задачи
Integrate application security best practices into the development lifecycle and enable automated security checks within CI/CD pipelines; Support and maintain application security tooling, including SAST, DAST, SCA, and secrets scanning; Help developers interpret and remediate security findings; Conduct secure code reviews, threat modeling sessions, and application architecture assessments; Develop and maintain security automation, guardrails, and reusable components; Assist in defining and improving secure coding standards and application hardening practices; Improve application-level logging, telemetry, and alerting; Support incident response activities related to application vulnerabilities, including verification, triage, and remediation; Stay current on emerging threats, vulnerabilities, and application and product security practices; Contribute to documentation, including security requirements, guidelines, and remediation playbooks; Participate in internal security reviews, compliance-driven assessments, and architectural walkthroughs; Develop and help maintain application security tools, pipelines, and workflows; Collaborate with engineering and product teams to ensure secure application deployment and continuous improvement.
требования
Bachelor’s degree in Computer Science, Engineering, MIS, or equivalent practical experience; 2–5 Years of experience in application security, product security, software engineering with a security focus, or a related technical role; Strong understanding of application vulnerabilities and mitigation strategies, including OWASP Top 10 and CWE; Experience with CI/CD tooling, Git-based workflows, and modern development practices; Familiarity with cloud security concepts and hands-on experience with AWS, Azure, or GCP; Experience with Python, Go, Java, JavaScript/Typescript, or Ruby; Experience with application security tools such as OWASP ZAP, Burp Suite, SAST/DAST tools, SCA, or dependency scanning; Knowledge of secure coding principles, API security, authentication, authorization, and secrets management; Strong problem-solving skills and ability to communicate technical issues clearly to developers and cross-functional stakeholders; Understanding of agile development processes and working within engineering teams; Ability to travel 25% in person.
условия
Competitive pay and attractive stock grants; Flexible paid time off; The role requires onsite work 1–2 days per week.
Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.
Про зарплаты
Анонимные данные по зарплатам и грейдам. Можно сверить вилку с рынком.
Посмотреть зарплаты
статьи для DevOps-инженеров