Application Security Engineer / Penetration tester
GroweRemotely
securitypenetration testingsastscaowasp top 10burp suitenucleisecret scanning
Job Description
📋 Description
- Triage security findings from SAST, SCA, and secret scanning tools; prioritize and track
- Perform manual and tool-based code reviews for security flaws before production.
- Conduct hands-on penetration testing of web apps, microservices, and APIs.
- Audit REST and GraphQL APIs and web apps focusing on auth, authZ, and business logic.
🎯 Requirements
- 3 years in Application Security, Product Security, or Penetration Testing.
- Experience triaging findings from Semgrep/OpenGrep, Gitleaks, Trivy, OSV-Scanner.
- Bonuses with Burp Suite Pro, Nuclei, Subfinder, SQLmap, Metasploit, NetExec.
- Deep OWASP Top 10 knowledge; injections, SSRF, XSS, CSRF, IDOR/BOLA, misconfigurations, crypto
- OWASP API Security Top 10 for REST/GraphQL.
- Identity protocols: OAuth 2.0, OIDC, JWT, SAML; RBAC/ABAC.
🎁 Benefits
- Growe culture focusing on teamwork and delivering results.
- Emphasis on adaptability and continuous improvement.
- Opportunity to work across security domains with cross-functional teams.