The position is for a Senior Application Security Engineer at a leading VPN company focused on privacy, security, and control.
The role involves ensuring software design security and defining secure implementation practices by collaborating with product development teams.
The engineer will facilitate smooth security-related communication between technical teams involved in product releases.
Responsibilities include developing scripts and security automation tools to enhance application security testing processes.
The engineer will create tasks for security reviews, cooperate with product teams to understand changes, and ensure thorough testing of mobile/desktop applications and browser extensions.
The role also includes supporting internal and external audits, designing and delivering security engineering training, and identifying internal security gaps.
The engineer will address security questions and provide advice on the product's security direction.
Requirements:
Candidates must have proven experience in mobile/desktop applications security assessment, including planning, testing methodologies, and vulnerability reporting.
A good understanding of network operations, particularly focusing on VPNs, is required.
Experience in working with stakeholders to define the scope of security tests and identify remediation actions for vulnerabilities is essential.
Knowledge of secure coding practices, especially regarding low-level languages like C, C++, and Rust, is necessary.
A sense of ownership, strong problem-solving, and investigation skills are important for this role.
Experience with security topics across various operating systems (Linux, Android, iOS, macOS, Windows) is required.
The ability to build and maintain relationships and influence key stakeholders is crucial.
Candidates should be able to make product-related business decisions based on identified threats and vulnerabilities.
A combination of assertiveness and the ability to compromise is also needed.
Benefits:
The company offers the opportunity to innovate alongside industry leaders and build world-class cybersecurity tools that impact millions of users.
Employees can enhance their skills through extensive training programs and mentorship opportunities for career growth.
A hybrid work model is available, allowing for three office days and two days of remote work.
Employees can work from any location to recharge their creativity.
The company promotes physical well-being with online workouts led by experts.
Mental and emotional health support includes free psychologist consultations and access to wellness apps like Calm and Headspace.
Private health insurance is provided for peace of mind regarding health needs.
Employees receive special gifts for significant life events such as birthdays and anniversaries.
The company organizes team-building events and celebrations to foster strong relationships among employees.
Employees can participate in company getaways abroad, featuring various activities and workshops.