
Senior Application Security Engineer
- Singapore
- Permanent
- Full-time
- Threat modeling: Think about how attackers can compromise a system and what protections are needed against them
- Secure Software Development Lifecycle: Help developers write secure code that minimizes vulnerabilities by implementing secure coding standards, techniques, and best practices
- Security code reviews: Identify security vulnerabilities in source code before an application is deployed to production
- Vulnerability testing and analysis: Discover weaknesses once an application is deployed and advise development teams on remediation
- Conduct security assessments for software components developed in the company.
- Validate external security reports and bug bounty submissions.
- Take part in the SLDC process development and implementation.
- Conduct post-mortem reviews of application security bugs.
- Consult engineers on application security matters, train them on secure development practices.
- Understanding of security models of Web/REST API, cloud, mobile and desktop apps.
- Hands on experience with security assessment tools and attack techniques. You should be able to go well beyond inserting a quote in URLs.
- Code assessments in programming languages Go, Python, Ruby, C/C++, JavaScript. Basic programming skills with Go, Python or another language will come handy.
- Strong communication skills.
- 2+ years in Application Security
- Strong knowledge of the modern web, mobile, and network security
- Published security research, open source tools, blog posts, proven history of bug bounty programs participation considered a strong advantage.
- Please be ready to answer in an interview the following questions:
- What is the Same Origin Policy? Share your knowledge about Cross-site scripting contexts
- Describe any attack like SQL injection, XXE, SSRF, or any other. Suggest right fixes and possible bypasses
- (Windows Security) Your opinion about LPE from Admin to the System user
- How to count possible compromised accounts?
- Be ready to write a simple exploit or a few lines of code that allows checking some kind of attacking vector
- Please submit your resume and application in English