Application Security Engineer
As an Application Security Engineer at CyberBlade, you play a key role in securing our clients' applications by identifying, analyzing and mitigating risks across the software lifecycle, from design through deployment.
What you will do
Secure Code Review
Conduct manual and automated source code reviews to identify vulnerabilities and recommend security improvements.
Application Penetration Testing
Perform security testing on web, mobile and API applications, simulating real-world attacks to uncover weaknesses.
Threat Modeling
Analyze application architecture and design to proactively identify potential security risks and provide mitigation strategies.
DevSecOps and Security Automation
Collaborate with DevOps teams to integrate security tools and processes into CI/CD pipelines for continuous testing and compliance.
Security Training and Awareness
Guide and train developers on secure coding practices, common vulnerabilities such as the OWASP Top 10, and secure development principles.
Vulnerability Management, Tooling and Incident Support
Track, prioritize and help remediate vulnerabilities, build or enhance security tooling, and assist in investigating application security incidents.
What we are looking for
- Application security expertise. Proven experience securing web and mobile applications, with a deep understanding of vulnerabilities such as SQL injection, XSS, CSRF and SSRF.
- Secure development knowledge. Strong grasp of secure coding practices across languages such as Python, Java, JavaScript, C# or Go.
- Penetration testing and security tools. Hands-on experience with Burp Suite, ZAP, SAST and DAST solutions, and fuzzing tools.
- Threat modeling and risk assessment. Experience performing threat modeling and assessing risk in application architectures.
- DevSecOps and CI/CD integration. Familiarity integrating security tools into DevOps workflows using GitHub Actions, Jenkins, GitLab CI/CD or Azure DevOps.
- Cloud security knowledge. Experience securing applications deployed on AWS, Azure or Google Cloud.
- Scripting and automation. Ability to develop scripts or tools in Python, Bash or PowerShell to automate security tasks.
Let's put your defenses to the test.
Whether you are a CEO or an individual in a home office, we keep pricing fair and stay in your corner long after the engagement ends. Tell us what you are protecting.