استخدام Senior Application Security Engineer
شرح موقعیت شغلی
We are looking for a Senior Application Security Engineer to design, build, and own secure software delivery across our engineering organization.
Key Responsibilities:
Application Security
- Design, implement, and operate pipelines across GitLab CI/CD.
- Integrate and tune SAST, SCA, DAST, secret detection, IaC scanning, and container image scanning.
- Generate and manage SBOMs; operate OWASP Dependency-Track as the central component inventory.
- Operate Semgrep and SonarQube for code quality and security hotspot triage.
- Perform manual source-code security reviews on Java and Laravel/PHP applications.
- dentify injection, access-control, deserialization, SSRF, file-upload, cryptographic, and business-logic weaknesses.
- Correlate source-code review findings with penetration test results to confirm exploitability and root cause.
- Validate scanner findings, eliminate false positives, and translate results into actionable developer guidance.
Web & API Penetration Testing:
- Test against OWASP Top 10, OWASP API Security Top 10, and the OWASP Web Security Testing Guide (WSTG) as a baseline methodology.
- Exploit and demonstrate impact for authentication and session flaws, broken access control (IDOR, horizontal/vertical privilege escalation), SSRF, injection (SQLi, NoSQLi, template, command), file-upload, and request-smuggling issues.
- Review and test authentication/authorization stacks: OAuth 2.0, OIDC, SAML, JWT handling, and SSO integrations. • Chain findings into realistic attack paths and produce proof-of-concept exploits that show real business impact rather than raw findings.
- Leverage industry-standard tooling (Burp Suite Pro, ffuf, nuclei, sqlmap)
مهارتهای مورد نیاز
- CI/CD
- Gitlab
- Laravel
حداقل سابقه کار
- سه تا شش سال
جنسیت
- مهم نیست
وضعیت نظام وظیفه
- مهم نیست