Application Security Engineer / Penetration tester
Name · Remote
Skills in this posting
Extracted from the posting text by the instrument — the demand side, read literally.
The posting
Growe welcomes those who are excited to
Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation;
Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production;
Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws;
Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorization, and business logic.
We need your professional experience
2-4 years of experience in Application Security, Product Security, or Penetration Testing;
Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner;
Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec;
Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment;
Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures;
Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC);
Ability to identify complex authorization bypasses, session management flaws, and business logic bugs;
Ability to read and analyze modern application code to spot security flaws (will be a plus);
Understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals (will be a plus);
Intermediate level of English (spoken and written).
We appreciate if you have those personal features
Strong communication skills to effectively collaborate with engineering, product, and DevOps teams;
Result-oriented mindset;
Openness to learning.
We are seeking those who align with our core values
GROWE TOGETHER: Our team is our main asset. We work together and support each other to achieve our common goals;
DRIVE RESULT OVER PROCESS: We set ambitious, clear, measurable goals in line with our strategy and driving Growe to success;
BE READY FOR CHANGE: We see challenges as opportunities to grow and evolve. We adapt today to win tomorrow.
Originally posted on Himalayas
Excerpt from the original listing. The full, current text lives at the source. Read and apply there →
The PivotHop read
- What a security engineer actually earnsmedian, seniority, by country
- Careers a security engineer can move intoevery measured route out
- All open security engineer rolesthe full board
Where these skills also reach
Adjacent occupations measured from the same postings — readiness is what a security engineer’s profile already covers.
- 63 open network engineer roles68% readiness from security engineer
- 24 open penetration tester roles66% readiness from security engineer
- 271 open systems administrator roles46% readiness from security engineer
- 568 open solutions architect roles38% readiness from security engineer
More security engineer roles
- Security EngineerXtxmarketstechnologies · London
- Sr. Security Engineer - GRC EU/UK Regulation & Data ProtectionXai · London
- Infrastructure Security EngineerXai · London
- Staff CIAM Security EngineerAffirm · United States
- Palo Alto Networks Security EngineerArctiq · Canada
Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.