Senior Application Security Specialist
Own security initiatives end-to-end by identifying, assessing, and driving remediation of vulnerabilities across products and infrastructure. Lead AppSec work, set security standards, balance risk against business velocity, mentor junior specialists, and document findings clearly.
Responsibilities
- Lead triage of bug bounty reports and scanner findings.
- Set severity standards, escalation policies, and remediation SLAs.
- Plan and conduct penetration tests of web applications, APIs, and services.
- Define assessment scope and methodology.
- Facilitate threat modeling sessions and identify trust boundaries, data flows, and attack surfaces.
- Select, operate, and tune SAST, DAST, SCA, and secrets-scanning tooling.
- Design noise-reduction and auto-triage workflows and integrate security gates into CI/CD.
- Lead secure code reviews across PHP, Python, and Go codebases.
- Define secure coding guidelines and review checklists.
- Coach junior security specialists, run internal training, and champion security awareness.
- Document findings, reproduction steps, and remediation guidance.
- Set the security documentation standard for the team.
Requirements
- 4+ years in application security or a related security engineering role.
- Expert knowledge of OWASP Top 10, SSRF, deserialization, request smuggling, OAuth/OIDC flaws, and business logic abuse.
- Extensive hands-on Burp Suite and manual testing experience.
- Ability to audit PHP, Python, Go, or JavaScript code.
- Experience embedding security requirements, design review, CI/CD gates, and developer enablement into workflows.
- Ability to assess severity and communicate risk to engineers and leadership.
- Strong analytical thinking, ownership, and follow-through.
- Nice-to-have experience with bug bounty programs, CTFs, Python or Go automation, GCP, Kubernetes security, advanced certifications, regulated environments, CVE credits, or security research.