✓ Drop your CV once, then continue to the employer's application form. Your profile stays here for every recruiter hiring on igamingjobs.
Role in brief
SOFTSWISS is looking for a Senior Application Security Engineer to enhance application security in their software development lifecycle. Candidates with over five years of experience in application security and a deep understanding of web vulnerabilities should apply.
About the role
As a Senior Application Security Engineer at SOFTSWISS, you will play a critical role in improving application security across the development lifecycle. You will lead threat modeling and risk assessments, ensuring that security requirements are clear and actionable for product teams.
In this role, you will conduct in-depth manual code reviews and manage the bug bounty program. Your expertise will help build secure code development processes and enhance the security posture of applications used by millions. Collaboration with Dev/QA teams will be essential for providing ongoing security guidance.
Skills that matter here
- Application Security: This role requires extensive experience in application security to identify and mitigate vulnerabilities effectively.
- Web Application Security: A deep understanding of web application security mechanisms is crucial for addressing complex security threats.
- Secure Development Processes: Knowledge of secure development best practices will be necessary to contribute to secure code development.
- Vulnerability Assessment: Hands-on expertise in identifying vulnerabilities through security assessments will be key to improving application security.
Who this role suits
- A seasoned professional with over five years of experience in application security.
- Someone who thrives in a collaborative environment and enjoys sharing knowledge with teams.
- An individual with a strong analytical mindset, capable of conducting deep root-cause analysis.
- A proactive problem solver who is committed to maintaining high security standards.
From the employer
- Partner with product teams during the design phase to lead threat modeling and risk assessments sessions, translating complex security threats into clear, actionable security requirements.
- Perform in-depth manual code reviews on critical applications to identify complex logical vulnerabilities as part of white-box security assessment.
- Plan, design, implement, automate and (if you wish) support AppSec tools.
- Contribute to building a company-wide processes for secure code development and deployment.
- Triage identified security vulnerabilities, provide clear and actionable descriptions and ensure these findings are properly addressed and mitigated.
- Manage the bug bounty program, collaborate with researches and internal teams to resolve the discovered vulnerabilities.
- Partner with Dev/QA teams throughout the development lifecycle to enhance the application's security posture by providing expert consulting, continuous knowledge sharing, and actionable security guidance.
- 5+ years of experience in Application Security.
- Knowledge of secure development processes and best practices.
- Deep understanding of web application security mechanisms (i.e., how the web actually works? What is SOP and why do we need CORS? What is CSP?).
- Deep understanding of common web application vulnerabilities (i.e., OWASP Top 10), and the most effective ways to prevent them.
- Knowledge of secure system/application architecture and design principles.
- Understanding of modern threats to high-performance web applications that are used by millions of users daily.
- Understanding of modern authentication/authorisation patterns (OAuth, OIDC, JWT, etc.).
- Practical hands-on expertise in identifying vulnerabilities through security assessment and secure code review, coupled with the ability to perform deep root-cause analysis to drive systemic fixes.
- University degree in Computer Science, Information Security, or related field, or equivalent combination of education and experience.
- Private health insurance
- Sports benefits
- Comprehensive Mental Health Program
- Free English lessons (online)
- Local language courses
- Paid time off
- Maternity leave support
- Referral program rewards
- Upskilling, internal workshops, and participation in professional conferences and corporate events
Questions about this role
What is the remote policy for this role?
This position is fully remote.
What is the required experience for the role?
Candidates should have over five years of experience in application security.
✓ Drop your CV once, then continue to the employer's application form. Your profile stays here for every recruiter hiring on igamingjobs.