- Home
- Remote Jobs
- Senior Application Security Engineer
Date Posted
5 days ago
New!Remote Work Level
Option for Remote
Location
Argentina, Spain, Uruguay
Job Schedule
Full-Time
Salary
We're sorry, the employer did not include salary information for this job.
Benefits
Professional/Career Development
Categories
IT, Cyber Security, Software Engineer, Python, Ruby on Rails
Job Type
Employee
Career Level
Experienced
Travel Required
No Specification
Education Level
We're sorry, the employer did not include education information for this job.
About the Role
Senior Application Security Engineer
Locations:
- Remote (UTC-5 to UTC+3 time zones)
- Argentina
- Spain
- Uruguay
Office Locations:
- Buenos Aires, Argentina
- Córdoba, Argentina
- Montevideo, Uruguay
- Barcelona, Spain
Work Arrangement: Remote or Hybrid
Job Type: Full-time
The Information Security Team is in charge of identifying, evaluating, reporting and mitigating risks to acceptable levels that meet compliance and regulatory requirements. From corporate systems and users’ security, creating security awareness programs, working with development teams to securely design features to enable new markets and products, to incident detection and remediation, the team maintains the corporate wide information security program to ensure that information assets are adequately protected, aligned with the company vision, mission, culture and business objectives.
About the Position
For this role in the Information Security Team we are looking for someone who is passionate about adding security controls to our software development life cycles. This person will be responsible for assessing that the technology we develop is up to date with industry standards for maintaining confidentiality, integrity and availability.
The ideal candidate is looking to show and technically explain the security weaknesses identified when developing technology, how attackers could take advantage of them and provide security education to teams to mitigate these risks
Location
Remote work from anywhere between UTC-5 and UTC+3 time zones. Office locations include Buenos Aires, Cordoba, Montevideo, Barcelona.
Responsibilities
As a Senior Application Security Engineer, you will be responsible for:
- Integrating security knowledge and expertise into the current technology development lifecycles. This includes performing threat modeling, code reviews and vulnerability assessment.
- Assisting each stakeholder as to the best approaches to mitigate the identified risks.
- Defining and following a software security initiative maturity model, constantly improving the processes associated with developing technology securely.
- Design, build and maintain, in collaboration with the Platforms and Infrastructure team, solutions that add support into our SDLC processes, constantly automating repetitive tasks identified throughout the different initiatives. This includes Static and Dynamic Code Analysis, among others.
- Document and share internally security best practices for technology development.
- Being the main point of contact (and subject matter expert) between application and hardware development and the Information Security teams.
About you
Experience
- At least 10 years of experience doing application pentesting, source code audits, architectural reviews, or similar security services. Although we appreciate and value security scanners, we will require scanner-less experience performing assessments.
Skills
- Strong familiarity with SSDLC processes, source control and CI/DI pipelines. Experience with maturity models (eg. BSIMM) is a plus.
- Advanced familiarity with AI Driven SDLC processes, aiming at automating detection, triaging and fixing identified problems.
- Advanced programming skills: high level languages like Python, Ruby, Go.
- Intermediate skills: low level languages like C, C++, ASM.
- Strong knowledge of cryptography, secure protocols and vulnerabilities introduced by misusing this technology.
- Strong knowledge of Identity Access Management protocols (e.g. SAML, OAuth, OIDC, etc.) and products, and how to implement authentication and authorization securely.
- Solid understanding of networking protocols, security architectures and products.
- Knowledge of cloud infrastructure (AWS, GCP) from an attacker’s perspective.
- Advanced use and administration of Windows and Unix operating systems.
What we value
- Demonstrated mindset of thinking like an attacker.
- Solid communication skills and the ability to clearly articulate complex ideas and plans.
- Advanced English proficiency.
- Purpose-driven, resourceful and able to deliver results autonomously.
- Respect and support for all employees.
- Ability to understand and manage differences and discrepancies by making decisions and proposing alternative solutions.e together to do their best work.