Matomo

Application Security Engineer | Cossack Labs
Back to jobs

Application Security Engineer

Reviewing and improving software security.

This position is open exclusively for Ukrainian residents within Ukraine (preferably Kyiv or Lviv).

We are looking for an Application Security Engineer to join our Security Engineering team and work with us on building and breaking software. If you are interested in designing and building security controls, working hand-in-hand with software developers, performing security assessments, this could be the position for you.

We are ready to invest time in your education if you are prepared to work diligently and responsibly. Alongside technical skills, we’ll teach you leadership, time management, business context, and how to keep improving cybersecurity despite the ever-increasing entropy of the world.

You will #

  • Perform security assessment and review of code and behaviour of systems (web, API, backends).
  • Perform risk analysis and threat modelling.
  • Perform security search for weaknesses and vulnerabilities in software in novel fields and areas.
  • Participate in SSDLC for our products and our customers’ products. Explain risks & threats, work with developers to select security controls that would improve security without restricting usability/performance.
  • Take part in shaping and improving organisation’s security practices together with internal teams and business owners (assessing risks, developing security policies, and helping teams build more secure systems and processes).
  • Communicate about security technical topics with both technical and non-technical audiences (C-level managers, developers, product owners).
  • Dive into application security, infrastructure security, cloud and on-prem infrastructures, dedicated hardware, IoT security, ML security, and weird stuff beyond casual imagination with our team of skilled engineers. See example of our work.
  • Stay updated with emerging security threats, vulnerabilities, and controls by reading articles, papers, and NIST guidelines. Follow CVE updates and understand how the threat landscape is changing.
  • Contribute to open-source standards such as OWASP standards and guidelines.

We would expect you to have #

  • 3+ years as an Application Security Engineer or similar position.
  • Experience in performing security assessment for web applications and cloud systems.
  • Experience designing and implementing security processes and security controls in a technically diverse environment.
  • Be familiar with application security verification and software maturity frameworks: OWASP SAMM, OWASP ASVS, OWASP MASVS.
  • Understanding SSDLC and its difficulties: OWASP SSDLC, NIST SSDF.
  • Communication skills: you will communicate about security technical topics with both technical and non-technical audiences (C-level managers, developers, product owners).
  • An overall understanding of what information security is, how real-world risks and threats affect the choice of security controls. How to combine detective, preventive and corrective controls.
  • Experience in popular security tools required for the job, or ability to learn them quickly (Burp Suite, network analysers, various SAST and DAST, dependency and vulnerability scanners).

As a plus you’d have #

  • A certain area of expertise and deep interest in web, mobile, IoT, infrastructure – an area where you have “seen things” and ready to share experience.
  • Basic knowledge in cryptography: understanding the differences between symmetric and asymmetric cryptography, hashing, KDF.
  • Knowledge in one of several business domains: banking finance/payment processing, cryptocurrencies, IoT, hardware and ICS.
  • Understanding security standards and methodologies (NIST, ISO, CMMI, SOC).
  • Understanding risk management and threat modelling (NIST RMF, FAIR, STRIDE, MITRE ATT&CK).
  • Practical experience in scripting languages: Python or Bash.

Don’t see yourself in every requirement?
We’d still like to hear from you.

Hiring Process #

  1. Resume review – up to 5 business days.
  2. Test task – estimated time 3-4 hours.
  3. Introductory meeting with the Head of security engineering.
  4. Technical interview with several team members.
  5. Background check.
  6. Offer discussion.

What we offer #

  • Opportunities to work across technologies and projects: cryptography, software engineering, information security, ML security controls, cryptographic protocols, hardware protection, reverse-resilient mobile apps, and web apps for millions of users.
  • Quarterly performance reviews, regular one-on-one meetings with your manager, and ongoing support to help you succeed and grow professionally.
  • Quarterly compensation reviews, aligning pay with performance and market benchmarks.
  • Performance and reward bonuses.
  • 21 business days of vacation, plus sick, mental health, and emergency days to use when genuinely needed.
  • Combination of in-office and remote work as needed, flexible scheduling, and a winter slowdown period.
  • Conferences, books, courses, internal knowledge sharing, workshops, writing blog posts and research papers, giving talks, and contributing to open-source parts of our products — choose what aligns with your professional goals.

Why work at Cossack Labs? #

You’ll work alongside PhDs in information security and cryptography, contributors to infosec community standards, specialists in rare security topics, and business-centric security engineers with broad experience. Some have worked in infosec since the 1990s, helping shape the industry and write the standards it relies on today.

For newcomers, we offer detailed onboarding during the first weeks. At Cossack Labs you’ll discover what works for you and what you need to learn next, developing through hands-on work on challenging problems, mentoring, and continuous learning with personal development plans to guide your growth.

Working at Cossack Labs, you’ll be at the cutting edge of technology and real-world security projects alongside highly skilled professionals who genuinely care about building a safer and more secure future.

Apply for the position

Our team will review your CV and provide feedback
within 5 business days

Share this opportunity

Start a conversation

Get whitepaper

Application form

Our team will review your resume and provide feedback
within 5 business days

Thank you!

We’ve received your request and will respond soon.

Your resume has been sent!

Our team will review your resume and provide feedback
within 5 business days