Application Security Engineer Offline
Weβre BrainRocket β an international software development and digital solutions company driven by 1,300 talented professionals across Cyprus, Poland and Portugal.
Here, everything moves at rocket speed: driving innovation, pioneering projects, and fast-tracking careers.
Together, we turn ideas into actionβletβs get started!
We invite a Senior Application Security Engineer to join our team remotely.
β
Responsibilities:
βοΈ Demonstrated ability to collaborate with other teams to achieve complex objectives.
βοΈ Responsible for security architecture design from cloud infrastructure to application through the implementation of "secure by design" principles.
βοΈ Collaborate with product managers, architects, and developers on the implementation of the security controls platform ecosystem and products.
βοΈ Proof security implementations within infrastructure and application deployment manifests and the CI/CD pipelines.
βοΈ Define required policies, controls, and capabilities for the protection of products and environments.
βοΈ Build and validate declarative threat models automation.
βοΈ Participate in engineering teamsβ product planning cycles and committees.
βοΈ Oversee the product security aspects for migration of products and services from Data Center to public cloud, e.g., AWS.
βοΈ Serve as a trusted cyber security advisor to product and application teams.
β
Minimum Requirements:
βοΈ Experience integrating security scanning/tooling into the development pipeline.
βοΈ Experience in analyzing and securing microservices and applications developed using Javascript and Typescript.
βοΈ Experience with CI/CD pipelines (such as Gitlab, Jenkins) and infrastructure-as-a-code models (such as Terraform, Helm, or CloudFormation).
βοΈ Hands-on development experience in Python/shell scripting.
βοΈ Strong understanding of supply chain security, software integrity, and secure software delivery.
βοΈ Experience with docker and mesh technologies (such as ISTIO).
βοΈ Experience with architecture and security reviews, threat modelling and application risk is highly desired.
βοΈ Experience working with Agile methodologies.
βοΈ Knowledge of privacy laws and regulations, such as GDPR desired.
βοΈ Familiarity with industry regulations, frameworks, and practices. For example, PCI, ISO 27001, NIST, etc.
β
PREFERRED QUALIFICATIONS:
βοΈ In-depth experience with architecting secure services on Kubernetes.
βοΈ Extensive experience with architecting secure services on AWS or on-prem data centres.
βοΈ Security-related professional certifications e.g., CISSP, CISM, CCSK, CCSP, CEH is highly desirable.
β
We offer excellent benefits, including but not limited to:
π§π»βπ» Learning and development opportunities and interesting, challenging tasks.
π Opportunity to develop language skills, with partial compensation for the cost of English classes.
π Time for proper rest, with 20 working days of annual vacation.
π Competitive remuneration level with annual review.
π€ Teambuilding activities.
Bold moves start here. Make yours. Apply today!
The job ad is no longer active
Look at the current jobs Security β