Junior Application Security Engineer
Kyiv, Ukraine・Lviv, Ukraine・Full time・Flexible Remote // Reviewing and improving software security.
The opportunity: #
This position is open exclusively for Ukrainian residents within Ukraine (preferably Kyiv or Lviv).
We are looking for a Junior Application Security Engineer. If you are interested in performing security assessments and working hand in hand with security engineers and software developers, this could be the position for you!
We are ready to invest time in your education if you are prepared to work diligently and responsibly. Alongside technical skills, we’ll teach you leadership, time management, business context, and how to keep improving cybersecurity despite the ever-increasing entropy of the world.
We are a data security solutions company, providing custom bespoke solutions to innovative software development teams around the world. Our software is well-known amongst security-aware teams, recommended by OWASP, and popular for easily solving complicated security challenges. Apart from building “off-the-shelf” solutions, we design custom security controls for novel problems.
We work in the B2B space, with customers such as IIoT, AI / ML based systems, mission critical systems, robotics, navigation, power grid operators, payment processors, financial apps, legal companies, million-user customer applications. We cater to young ambitious startups and well-established enterprises, who use our software and solutions as core part of their security arsenal. Our customers are smart, but extremely demanding.
Markets: EU, UK, USA, UA.
Sounds interesting?
You will: #
- Perform security assessment and review of code and behaviour of systems (web, API, backends, Linux). Mostly whitebox, occasional blackbox.
- Perform security search for weaknesses and vulnerabilities in software in novel fields and areas.
- Participate in SSDLC for our products and our customers’ products. Explain risks & threats, work with developers to select security controls that would improve security without restricting usability/performance.
- Dive into application security, infrastructure security, cloud and on-prem infrastructures, dedicated hardware, IoT security, ML security, and weird stuff beyond casual imagination with our team of skilled engineers. See example of our work.
- Stay updated with emerging security threats, vulnerabilities, and controls by reading articles, papers, and NIST guidelines. Follow CVE updates and understand how the threat landscape is changing.
We would expect you to have: #
- 1+ years as an Application Security Engineer or similar position.
- Experience in performing security assessment for web applications and cloud systems.
- Be familiar with application security verification frameworks: OWASP ASVS.
- Understanding SSDLC and its difficulties: OWASP SSDLC, NIST SSDF.
- An overall understanding of what information security is, how real-world risks and threats affect the choice of security controls. How to combine detective, preventive and corrective controls.
- Experience in popular security tools required for the job, or ability to learn them quickly (Burp Suite, network analysers, various SAST and DAST, dependency and vulnerability scanners).
As a plus you’d have: #
- A certain area of expertise and deep interest in web, mobile, IoT, infrastructure – an area where you have “seen things” and ready to share experience.
- Basic knowledge in cryptography: understanding the differences between symmetric and asymmetric cryptography, hashing, KDF.
- Be familiar with NIST SP 800-53.
- Be familiar with threat modelling (OWASP threat modelling, STRIDE, MITRE ATT&CK).
- Practical experience in scripting languages (Python, Bash, or even Javascript (meh)).
Hiring Process: #
- Resume review – up to 5 business days.
- Test task – estimated time 3-4 hours.
- Introductory meeting with the Head of security engineering.
- Technical interview with several team members.
- Background check.
- Offer discussion.
Please note that you can be a perfect fit even if not everything we’ve outlined above applies to you. If you have any questions, please don’t hesitate to ask – everyone is unique.
We offer: #
Unique area of expertise: #
- Interesting and challenging work in applied security engineering: from building to breaking.
- Working at the intersection of different areas: designing ML security controls, supporting cryptographic protocols with security controls, protecting hardware, building reverse-resilient mobile apps, securing web apps for million of users, etc.
- Combining technologies: cryptography, software engineering, information security. You won’t be bored :)
- Public track record in the open source part of our products, sharing your work as blogs posts, research papers and conference talks. We work with innovative companies all over the world, move quickly and dive into technologies others just hear about.
- A sense of meaning and responsibility for those who seek purpose – we’re building “invisible texture of modern civilization”—bits of infrastructure finance, power grids, healthcare rely on, and we are trusted with very challenging aspects of it.
Environment: #
- Friendly and experienced team: smart people to learn from, great people to build with. Each of us is unique, we value and support each other.
- An atmosphere that motivates you to grow and get smarter every month, a healthy ratio of routine / experimentation.
- Trust: schedule, reporting, bureaucracy is kept at reasonable minimum. We hire smart people and trust them to do the right thing. When things go wrong, we help rather than punish.
- Shared decision making: this business is driven by engineering excellence, so engineers are important part of tactical and strategical business decisions.
- Friendly to humans: not just a formal vacation and sick leave quota. Feel like your mental or physical wellbeing needs care? Take some time off. Feel like working a few days from home? Sure. As long as you’re in line, we are here to support you when you’re not.
Growth: #
- Team that facilitates internal learning and growth all the time.
- Interesting technologies to work with — sometimes, even unique ones (we design applied cryptography schemes and techniques and novel ways to use them).
- Interesting engineering challenges across the board, ability to hop from high-level system design to protocol reverse engineering and clever data modelling hacks.
- Management attention to help you improve upon your personal goals (through 1:1s and mentoring).
Benefits: #
- Competitive compensation with flexible bonus scheme.
- Sick leaves, 21 business days for vacation per year, extra days off — according to the agreements and laws.
- Conferences, books, courses — we encourage learning and sharing with the community. Our team members share a lot in talks, workshops and blog posts.
Not sure but considering? Talk to us. #
If you see yourself fit but a few things are off — don’t hesitate to talk anyway. It might be that your unique combination of skills and knowledge would be perfectly fitting for our environment, but we both just don’t know it yet.
How to apply?
We'd like to get your CV to start a conversation. A supporting letter explaining your story and experience in application security, what you have done in the past and what kind of work you find interesting would help, but is not necessary.
