Hiring.Camp

Application Security Engineer / Penetration tester

Growe

·

Today

Location
Anywhere · Warsaw, Masovian Voivodeship, Poland
Department
Cybersecurity
Experience
2+ years
Source
Greenhouse

Description

Growe welcomes those who are excited to:
  • Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation;

  • Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production;

  • Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws; 

  • Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorization, and business logic.

We need your professional experience:
  • 2-4 years of experience in Application Security, Product Security, or Penetration Testing; 

  • Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner;

  • Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec; 

  • Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment;

  • Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures; 

  • Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC);

  • Ability to identify complex authorization bypasses, session management flaws, and business logic bugs;

  • Ability to read and analyze modern application code to spot security flaws (will be a plus); 

  • Understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals (will be a plus);

  • Intermediate level of English (spoken and written).

We appreciate if you have those personal features:
  • Strong communication skills to effectively collaborate with engineering, product, and DevOps teams;

  • Result-oriented mindset;

  • Openness to learning.

We are seeking those who align with our core values:
  • GROWE TOGETHER: Our team is our main asset. We work together and support each other to achieve our common goals;

  • DRIVE RESULT OVER PROCESS: We set ambitious, clear, measurable goals in line with our strategy and driving Growe to success;

  • BE READY FOR CHANGE: We see challenges as opportunities to grow and evolve. We adapt today to win tomorrow.

Skills

AWSKubernetesPenetration TestingRESTGraphQLOAuthDevOpsMicroservices

Similar Jobs

30

Application Security Engineer

Instabug · CAIRO, Egypt

2 days ago

Application Security Engineer

Umusic · GBR-4PS, United Kingdom

3 weeks ago

Application Security Engineer

Canopytax · South Jordan Utah +1 · Remote

3 weeks ago

Application Security Engineer

USA - Current Open Positions · USA-TN NVL 1234 Martin St, United States of America

4 weeks ago

Application Security Engineer

INTAPP · Portugal Remote · Remote

4 weeks ago

Application Security Engineer

Heartflowinc · San Francisco, California · Hybrid

4 weeks ago

Application Security Engineer

Zocdoc · USA Remote +1 · Remote

4 weeks ago

Application Security Engineer

Leidos · 5612 Ashburn VA, United States of America

1 month ago

Engineer, Application Security

Cboe is always looking for · Chicago HQ OPO, United States of America · Hybrid

1 month ago

Application Security Engineer

Interact Software · Manila, PH

1 month ago

Application Security Engineer

Figure · Remote · Remote

1 month ago

Application Security Developer

Clio · Toronto, Canada +3 · Remote

1 month ago

Application Security Engineer

Alaan · Bengaluru, India

1 month ago

Application Security Engineer

Booz Allen Hamilton · USA, MD, Fort Meade (6910 Cooper Ave), United States of America

1 month ago

Application Security Engineer

Intermedia Intelligent Communications · Portugal · Remote

1 month ago

Application Security Engineer

Oneleet · US · Remote

1 month ago

Application Security Engineer

Rockstargames · Leeds, England, United Kingdom · Onsite

1 month ago

Application Security Engineer

Intercom · London, England +1

1 month ago

Application Security Engineer

Intercom · Dublin, Ireland

1 month ago

Application Security Engineer

Iqvia · Porto Salvo, Portugal

1 month ago

Application Security Engineer

Gnw · Richmond, Virginia, United States of America

1 month ago

Application Security Engineer

Virtru · Washington, DC - Remote · Remote

2 months ago

Application Security Engineer

Globe · NCR - WGC, Philippines

2 months ago

Application Security Engineer

Solventum · Remote - Pennsylvania, United States of America +1 · Remote

2 months ago

Application Security Engineer

Altenar · St Julians, Malta, Malta

2 months ago

Application Security Engineer

Smartrent · Phoenix, Arizona

2 months ago

Application Security Engineer

Thought Machine · Portugal, Lisbon · Onsite

2 months ago

Application Security Engineer

Oneleet · United States · Remote

2 months ago

Application Security Engineer

Ibkr · India

2 months ago

Application Security Engineer

Opal · San Francisco · Hybrid

2 months ago
Application Security Engineer / Penetration tester at Growe | Hiring.Camp