Application Security Engineer / Penetration tester
Growe TalentsRemotely
application securitypenetration testingowasp top 10burp suitenucleisemgreptrivygitleaks
Job Description
📋 Description
- Triages, validates, and prioritizes security findings from SAST, SCA, and secret scanners; filter
- Performs manual and tool-assisted code reviews to find security issues before production.
- Conducts hands-on pentesting of web apps, microservices, and APIs to uncover vulnerabilities.
- Audits REST and GraphQL APIs with focus on core security risks, auth, and business logic.
🎯 Requirements
- 3 years in Application Security, Product Security, or Penetration Testing.
- Hands-on triage/analyze findings from Semgrep/OpenGrep, Gitleaks, Trivy, OSV-Scanner.
- Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, NetExec.
- Deep knowledge of OWASP Top 10 vulnerabilities and API security (REST/GraphQL).
- Understanding of identity protocols: OAuth 2.0, OIDC, JWT, SAML; RBAC/ABAC.
- Ability to read and analyze modern application code for security flaws.
🎁 Benefits
- Health & Wellness focus
- Global medical coverage
- Growth opportunities
- Gym/stomatology/psychological service benefits
- Performance-driven rewards
- Dynamic work environment