R
robota.ua
Frontend
AppSec Engineer (Application Security Engineer)
C#PythonJavaScriptSASTDASTSCACI/CDDevSecOps
About the Position
We are looking for an experienced Application Security Engineer or Penetration Tester to help strengthen the security of our web and mobile applications. This is a hands-on role that combines penetration testing, secure code review, security engineering, and collaboration with development teams.
Responsibilities
- Plan, coordinate, and perform penetration tests of web and mobile applications
- Conduct infrastructure security assessments and security audits
- Identify vulnerabilities, threats, and security risks affecting web and mobile applications
- Clearly communicate identified vulnerabilities, their business impact, and recommended remediation actions
- Evaluate, recommend, and implement security solutions for web and mobile applications
- Perform secure code reviews and provide practical guidance to development teams
- Analyze security events and monitor the security posture of applications
- Implement and maintain security standards and controls within the Secure Software Development Life Cycle
- Integrate application security tools and security testing into CI/CD pipelines
- Investigate security incidents and recommend remediation and preventive measures
- Deliver training and awareness sessions on secure software development practices
- Work closely with developers, engineering teams, and other stakeholders to improve application security
Requirements
- At least three years of professional experience as a Penetration Tester, Application Security Engineer, or Security Engineer
- Hands-on experience conducting penetration tests of web and mobile applications
- Experience identifying, validating, and assessing the impact of application security vulnerabilities
- Ability to explain vulnerabilities, risks, and remediation recommendations to both technical and non-technical stakeholders
- Practical experience performing secure code reviews
- Basic proficiency in at least one programming language, such as C#, Python, or JavaScript
- Strong understanding of the Software Development Life Cycle
- Hands-on experience implementing or maintaining application security tools, including: Static Application Security Testing (SAST); Dynamic Application Security Testing (DAST); Software Composition Analysis (SCA)
- Familiarity with integrating security controls and testing tools into CI/CD pipelines and Secure SDLC processes
- Professional proficiency in Ukrainian and English at B2 level or higher
- Strong analytical, communication, and problem-solving skills
Benefits
- The opportunity to make a direct impact on the country’s employment market
- Collaboration with a team of highly skilled engineers and technology leaders
- Real influence over technical decisions and the evolution of our data architecture
- Clear opportunities to grow toward a Data Architect role
- 24 calendar days of paid annual leave
- Paid sick leave without formal medical documentation for the first three days of illness
- Medical insurance
- Access to a gym and wellness activities
- Company-supported mental health initiatives
- A supportive environment where your expertise, ideas, and professional growth truly matter
AppSec Engineer (Application Security Engineer)
View Original