security engineer

ориентир по рынку
вакансия зп не указана
в среднем 343 365 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Altium Limited, part of the Renesas Group and headquartered in San Diego, California, is a global software company providing a cloud-based platform that unites electronics design, supply chain, and manufacturing stakeholders.

задачи

  • Build and execute security regression testing;
  • Drive threat modeling across existing and new functionality;
  • Conduct targeted offensive security activities, including Red Team-style testing;
  • Identify real vulnerabilities based on a deep understanding of the platform and the OWASP Top 10 Web Application Security Risks;
  • Design and maintain security regression test suites covering critical application flows;
  • Ensure vulnerabilities, once fixed, are permanently prevented from recurring;
  • Integrate security regression into CI/CD pipelines;
  • Define coverage targets for security-critical areas such as auth, access control, APIs, and data flows;
  • Lead structured threat modeling sessions for existing system components, new features, and architectural changes;
  • Identify attack surfaces, abuse cases, and trust boundaries;
  • Translate threats into test cases, security requirements, and mitigation plans;
  • Ensure threat modeling becomes a continuous lifecycle activity;
  • Perform manual and automated security testing simulating real attacker behavior;
  • Focus on high-impact vulnerabilities rather than theoretical findings;
  • Validate exploitability and business impact;
  • Partner with engineering teams to reproduce issues, prioritize fixes, and validate remediation;
  • Continuously assess the platform against OWASP Top 10 categories;
  • Use deep product knowledge to find non-obvious, context-specific vulnerabilities;
  • Go beyond tooling like DAST and SAST to uncover logic flaws and abuse paths;
  • Review new features and changes for security risks, ensuring all changes are threat-modeled and covered by regression tests;
  • Act as a security gatekeeper without becoming a bottleneck by enabling teams with guidance and tooling;
  • Work closely with engineering, architecture, and SRE/platform teams;
  • Contribute to secure-by-design practices and support developers in understanding and fixing vulnerabilities;
  • Help scale security through reusable patterns, automation, and security guidance.

требования

  • Have 5+ years of experience in Application or Product Security;
  • Hold a Bachelor's Degree or equivalent of 12 years of work experience;
  • Possess strong hands-on experience in web application security testing, API security, and threat modeling methodologies;
  • Demonstrate a deep understanding of the OWASP Top 10;
  • Bring experience with manual penetration testing, security regression testing, and CI/CD security integration;
  • Demonstrate the ability to identify business logic vulnerabilities;
  • Possess a strong understanding of authentication, authorization, session management, multi-tenant architectures, and cloud-native systems;
  • Nice to have: experience in SaaS / multi-tenant platforms, familiarity with bug bounty programs, red teaming, and security automation frameworks, knowledge of AWS, identity systems and federation including SSO and MFA, background in software engineering with the ability to read and write code.

условия

  • Competitive benefits package alongside salary.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.