Application Security Engineer/Penetration Tester

Growe

Completely RemoteFull TimeInformation Technology
Posted Today

Job description

Responsibilities

  • Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools
  • Conduct manual and tool-assisted code reviews to identify security vulnerabilities and logic flaws
  • Perform hands-on penetration testing of web applications, microservices, and APIs
  • Audit REST and GraphQL APIs with a focus on authentication, authorization, and business logic

Requirements

  • 2-4 years of experience in Application Security, Product Security, or Penetration Testing
  • Hands-on experience with Semgrep, OpenGrep, Gitleaks, Trivy, and OSV-Scanner
  • Proficiency with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec
  • Deep understanding of OWASP Top 10 and OWASP API Security Top 10
  • Knowledge of identity protocols including OAuth 2.0, OIDC, JWT, SAML, and RBAC/ABAC
  • Intermediate level of English (spoken and written)

Preferred Qualifications

  • Ability to read and analyze modern application code
  • Understanding of AWS cloud security and Kubernetes (K8s) security fundamentals

About the Company

Growe values teamwork, driving results over process, and adaptability to change.

Skills & tools

Penetration TestingApplication SecurityOWASP

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 012-4 years AppSec or Pentesting experience
  2. 02Experience with Semgrep, Gitleaks, and Trivy
  3. 03Proficiency in Burp Suite, Nuclei, and Metasploit
  4. 04Deep understanding of OWASP Top 10
  5. 05Knowledge of OAuth 2.0, OIDC, and JWT
  6. 06Intermediate English proficiency
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches