Skip to main content
Back to jobs

Application Security Engineer (Remote in Bulgaria, Germany, Italy, Serbia, Turkey)

External
constructortech logoConstructortech Ā· Belgrade, Serbia
Full-timeOn-site1w ago
Application SecurityCI/CDDevSecOpsJavaScriptOWASPPython
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


Requirements

  • Knowledge of SBOM standards (CycloneDX, SPDX) and experience integrating SBOM tooling into CI/CD pipelines.
  • Knowledge of software composition analysis (SCA) tools.

Benefits

šŸ’» Choice of work equipment (e.g., laptop, monitor, etc.)šŸ‡¬šŸ‡§ English classes (iTalki - $130 monthly)ā° Flexible schedule (we usually work between 09:00/10:00 and 18:00/19:00 CET or EET)šŸ‘¶ Newborn bonus (€500 per child)🧠 Patent remuneration🌓 Paid leavešŸ§‘šŸ’» Remote work in locations without our officesHybrid work in locations with offices (2 days in-office, 3 days remote)Paid time offRemote work optionsFlexible schedulePerformance bonusParental leave

Additional Information

Our mission Constructor's mission is to enable all educational organisations to provide high-quality digital education to 10x people with 10x efficiency. With strong expertise in machine intelligence and data science, Constructor's all-in-one platform for education and research addresses today's pressing educational challenges: access inequality, tech clutter, and low engagement of students. Please send your resume in English only. We are seeking an Application Security Engineer with a strong background in web application security design, secure development practices, and vulnerability testing. This role also requires practical experience with Software Bill of Materials (SBOM) management and implementation, contributing to our secure SDLC and software supply chain risk reduction efforts. Duties and Responsibilities: Perform threat modeling, security architecture review, and design analysis for web applications and APIs. Conduct manual and automated security testing during development and pre-release stages. Design and implement security pipelines (including SAST and DAST) and integrate them into the SDLC process. Implement and manage SBOM generation and consumption processes across the SDLC. Collaborate with development teams to ensure timely remediation of identified vulnerabilities. Maintain security guidance aligned with OWASP best practices and provide trainings for development teams. Stay current with evolving application security threats, tools, and industry developments. Qualifications and Experience: 3-5 years of experience in application security, with a focus on web applications and API security. Good knowledge of at least one scripting or programming language (e.g., Python, JavaScript, C#, or Go). Experience with tools like OWASP ZAP, Burp Suite, Snyk, or similar. Familiarity with secure coding, DevSecOps, and container security concepts. Strong understanding of CVE, CVSS, and vulnerability disclosure workflows. Excellent command of business English.


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at constructortech? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect