Nebius

Nebius

Nebius enables B2B companies to build local hyperscaling cloud platforms with cost-effective GPUs, InfiniBand network, and 50% less compute cost. They offer managed Kubernetes and a launch-ready business model for innovative cloud solutions.

Internet Software & Services
51-250

Description

  • Build and maintain ASPM tools and their rules.
  • Identify, analyze, and remediate application security vulnerabilities using ASPM and related tools.
  • Collaborate with development teams to integrate security best practices into the SDLC.
  • Conduct manual and automated penetration testing of applications.
  • Develop and maintain secure coding guidelines for development teams.
  • Facilitate threat modeling and risk assessments for new and existing applications.
  • Stay current on emerging security threats, vulnerabilities, and mitigation techniques.
  • Serve as an application security subject matter expert for other teams.

Requirements

  • 4+ years of experience in application security.
  • Strong knowledge of common application security risks, including the OWASP Top 10, and how to mitigate them.
  • Experience with secure coding practices in Python, Go, Java, or JavaScript.
  • Proficiency in a common programming language such as Go or Python, with willingness to learn Go if necessary.
  • Hands-on experience with security testing tools such as Burp Suite, ZAP, and Semgrep.
  • Understanding of authentication protocols such as SAML or OIDC.
  • Experience conducting threat-modeling sessions.
  • Strong problem-solving and analytical skills.
  • Good written and verbal communication skills in English.
  • Willingness to learn new things and work independently.
  • Confidence presenting ideas and responding well to feedback is a plus.
  • Experience designing, building, and maintaining security automation is a plus.
  • Experience translating compliance and regulatory requirements into technical specifications is a plus.
  • Experience exploiting vulnerabilities in web applications, Linux kernels, containers, and networks is a plus.
  • Security certifications such as OSCP or OSWE are a plus.
  • Coding interviews are part of the hiring process.
  • Must be authorized to work in the country of application and provide proof of employment eligibility.

Benefits

  • Competitive compensation with a base salary range of €75,000 to €240,000 EUR.
  • Benefits package with compensation determined by experience, skills, qualifications, level, and location.
  • Career growth and learning opportunities.
  • Flexibility and ownership.
  • Collaborative and innovative culture.
  • Opportunity to work on impactful AI projects.
  • International environment with talented teams.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Application Security Engineer - Southeast region (Remote)

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is hiring a senior Application Security consultant to help client organizations strengthen and operationalize their AppSec programs through a mix of advisory work, hands-on engineering, and executive-level guidance.

AWS Azure CI/CD DevSecOps GCP Kubernetes Secrets Management
2 hours, 21 minutes ago

Security Engineer- Product Security

Spotify Media

Spotify is hiring a Security Engineer for Product Security to secure its platform, infrastructure, and engineering initiatives for hundreds of millions of users across London or Stockholm.

Agile C++ CI/CD Encryption Generative AI Java Python Scala TypeScript
2 hours, 36 minutes ago

Product Security Engineer

MLabs 11-50 Internet Software & Services

MLabs is hiring a Product Security Engineer to secure an enterprise-grade open-source proof-of-stake blockchain platform as it scales across protocol upgrades, EVM-compatible services, and cross-chain infrastructure.

Blockchain CI/CD Encryption gRPC Java Rust
2 hours, 51 minutes ago

Application Security Engineer

Inovalon 1K-5K IT Services

Inovalon is hiring a Staff Software Engineer focused on application security to embed secure practices across the design, development, and operation of cloud-native SaaS healthcare platforms.

Agile DevSecOps Encryption GCP HIPAA Penetration Testing
1 day, 5 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers