
Constructor Knowledge
Posted 1 month ago
Application Security Engineer (Remote in Bulgaria, Germany, Italy, Serbia, Turkey)
BelgradeRemoteFull-time
AI Summary
Application Security Engineer focusing on web app security design, threat modeling, SDLC security integration, SBOM management, and vulnerability remediation.
About this role
We are seeking an Application Security Engineer with a strong background in web application security design, secure development practices, and vulnerability testing. This role also requires practical experience with Software Bill of Materials (SBOM) management and implementation, contributing to our secure SDLC and software supply chain risk reduction efforts.
Duties and Responsibilities:
- Perform threat modeling, security architecture review, and design analysis for web applications and APIs.
- Conduct manual and automated security testing during development and pre-release stages.
- Design and implement security pipelines (including SAST and DAST) and integrate them into the SDLC process.
- Implement and manage SBOM generation and consumption processes across the SDLC.
- Collaborate with development teams to ensure timely remediation of identified vulnerabilities.
- Maintain security guidance aligned with OWASP best practices and provide trainings for development teams.
- Stay current with evolving application security threats, tools, and industry developments.
Qualifications and Experience:
- 3–5 years of experience in application security, with a focus on web applications and API security.
- Good knowledge of at least one scripting or programming language (e.g., Python, JavaScript, C#, or Go).
- Experience with tools like OWASP ZAP, Burp Suite, Snyk, or similar.
- Familiarity with secure coding, DevSecOps, and container security concepts.
- Strong understanding of CVE, CVSS, and vulnerability disclosure workflows.
- Excellent command of business English.
- Preferred Qualifications:
- Knowledge of SBOM standards (CycloneDX, SPDX) and experience integrating SBOM tooling into CI/CD pipelines.
- Knowledge of software composition analysis (SCA) tools.
Skills
Burp SuiteC++CI/CDContainer SecurityCVECVSSCycloneDXDASTDevSecOpsGOJavaScriptOWASP ZAPPythonSASTSBOMSBOM ToolingSCA ToolsSDLC SecuritySecurity Architecture ReviewSnykSPDXThreat ModelingVulnerability Disclosure Workflows
Explore related jobs
More jobs at Constructor Knowledge
Similar Burp Suite jobs
Jobs in Belgrade
- Pharmacovigilance Officer, Team Leader/Case Processing Manager (Line Management experience required)Ergomed · Belgrade, Serbia
- Senior Backend Engineer (Golang)SMG Swiss Marketplace Group · Belgrade, Serbia
- ZCarrier Sales Representative (On-site in Belgrade)Zelh · Belgrade, Beograd
- ZCustomer Service Rep (T&T)Zelh · Belgrade, Beograd
- ZAccount SpecialistZelh · Belgrade, Beograd
- ZCustomer Service RepZelh · Belgrade, Beograd