Application Security Engineer / Penetration tester
About this role
Our client, Growe, is a leading business advisory and services group in iGaming and Entertainment. Сreators of strategies that work and solutions that scale. Combining strategic vision with hands-on expertise, Growe helps businesses navigate the fast-evolving industry, seize new opportunities, enter new markets, and achieve sustainable growth.
Perfect for those who aim to:
-
Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation;
-
Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production;
-
Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws;
-
Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorization, and business logic.
Experience you’ll need to bring:
-
3 years of experience in Application Security, Product Security, or Penetration Testing;
-
Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner;
-
Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec;
-
Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment;
-
Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures;
-
Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC);
-
Ability to identify complex authorization bypasses, session management flaws, and business logic bugs;
-
Ability to read and analyze modern application code to spot security flaws (will be a plus);
-
Basic understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals (will be a plus);
-
Intermediate level of English (spoken and written).
It's a perfect match if you have those personal features:
-
Strong communication skills to effectively collaborate with engineering, product, and DevOps teams;
-
Result-oriented mindset;
-
Openness to learning.
Our clients offer competitive benefits to support your professional and personal growth, including:
-
Health & Wellness Focus;
-
Global Medical Coverage;
-
Growth Opportunities;
-
Benefits Programs (compensation for the gym/stomatology/psychological service & etc.);
-
Performance-Driven Rewards;
-
Dynamic Work Environment.
Apply, and let your growth journey begin.
Frequently Asked Questions
Is the salary disclosed for the Application Security Engineer / Penetration tester position at growetalents?
Is the Application Security Engineer / Penetration tester job at growetalents remote?
Which team or department does the Application Security Engineer / Penetration tester at growetalents belong to?
How do I apply for the Application Security Engineer / Penetration tester position at growetalents?
When was the Application Security Engineer / Penetration tester job at growetalents posted?
You'll be redirected to growetalents's official application page on Greenhouse.