Jobiglo

Aucun resultat.

Application Security Engineer

Swapcard · Cimetière de Bruxelles

Nouveau Remote
Remote 🇬🇧 English
Bug Bounty Burp Suite OWASP Top 10 SSRF IDOR SAST DAST SonarQube Snyk Jenkins Terraform Helm WAF anti-bot solutions CI/CD

Description du poste

About the role

Swapcard is looking for an Application Security Engineer to strengthen the security of its AI‑powered event platform. You will work remotely with a global team of developers, product owners and security specialists to embed security throughout the software development lifecycle.

Key responsibilities

  • Own and manage the Bug Bounty program: triage reports, validate findings and reproduce proofs of concept.
  • Collaborate with developers and product owners to propose and implement remediation for security issues.
  • Write or review pull requests that fix vulnerabilities directly in the codebase.
  • Validate external penetration‑test results and integrate findings into the development backlog.
  • Contribute to threat modeling, code reviews and security design discussions.
  • Support the Secure Development Lifecycle, including SAST, dependency scanning and security automation in CI/CD pipelines.
  • Perform lightweight pentesting of new features and releases when needed.
  • Maintain clear documentation for AppSec processes and coordinate security communication across teams.

Required profile

  • Previous experience as a developer on any modern backend or frontend stack.
  • Hands‑on security experience through bug bounty programs, CTFs or pentesting, using tools such as Burp Suite.
  • Solid understanding of common application vulnerabilities (OWASP Top 10, SSRF, IDOR, etc.).
  • Familiarity with SAST/DAST tools like SonarQube or Snyk.
  • Experience collaborating with developers and product teams and a strong “find and fix” mindset.

Required skills

  • Bug Bounty program management
  • Burp Suite
  • OWASP Top 10 knowledge
  • SAST and DAST tools (SonarQube, Snyk)
  • CI/CD platforms (Jenkins, GitLab CI)
  • Infrastructure‑as‑code tools (Terraform, Helm)
  • Web Application Firewalls and anti‑bot solutions
  • Security automation and developer enablement

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Swapcard.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Pourquoi signalez-vous cette offre ?

Merci pour votre signalement. Nous allons examiner cette offre.

Postulez en 30 secondes

Entrez votre email pour postuler. Un compte sera cree automatiquement.

En continuant, vous acceptez nos conditions d'utilisation.

Deja un compte ? Connexion

Publie il y a 2 heures

Expire dans 1 mois

3 vues · 0 candidatures

Boostez vos chances

Importez votre CV : nous vous proposons les offres qui matchent votre profil.

Analyse de votre CV en cours...

Swapcard

Cimetière de Bruxelles