Application Security Engineer

Andersen Ukraine 2025-07-02 21:04:58

Описание


Summary

The IT company Andersen invites Application Security Engineer to join our team and contribute to the development of our company while maintaining its unique culture and atmosphere.

Andersen is a European pre-IPO software development company uniting over 3,500 top-class professionals: developers, architects, testers, analysts, and other specialists. Operating in the market since 2007, we have developed 1,000+ outstanding projects for the Financial sector, Healthcare, Logistics, Travel and Hospitality, Telecom, Automotive industry, etc.


Responsibilities

Leading secure development initiatives, integrating security into the SDLC through threat modeling, secure code reviews, and CI/CD pipeline security controls (SAST/DAST/SCA). Overseeing penetration testing engagements, coordinating internal red team exercises and external assessments to identify vulnerabilities in web/mobile apps, APIs, and cloud services. Mentoring junior AppSec engineers and developers, providing training on secure coding practices (OWASP Top 10, SANS 25) and remediation guidance for critical flaws. Defining and enforcing security standards, ensuring compliance with industry frameworks (NIST SSDF, ISO 27034) while balancing business agility and risk tolerance.

Requirements

Experience in Application Security, penetration testing, or DevSecOps, combining strong technical expertise with team leadership skills for 5+ years. Possession of advanced offensive security certifications such as OSCP, OSWE, or GWAPT, along with secure coding credentials like CSSLP or CASE. A degree in Computer Science, Cybersecurity, or Software Engineering. A background in software development is highly valued. Strong advocate of shift-left security, with hands-on experience integrating tools like Semgrep, SonarQube, and Checkmarx into CI/CD pipelines. Experience leading purple team exercises in collaboration with developers to simulate real-world attacks (e.g., API abuse, SSRF) and improve secure coding practices. Deep understanding of cloud-native AppSec, including securing serverless applications, containers (Kubernetes), and Infrastructure as Code (Terraform) against misconfigurations and supply chain threats. Ability to communicate technical risks to executive stakeholders, translating them into business impact to support security investment decisions. Active participation in bug bounty platforms (e.g., HackerOne, Bugcrowd), CTF competitions, and ongoing research into emerging threats such as AI-generated code vulnerabilities and WebAssembly security. A hybrid hacker-developer mindset: capable of exploiting vulnerabilities (e.g., using Burp Suite) and reviewing pull requests for security anti-patterns. Level of English – from Upper- Intermediate+ and above.

Reasons to join us

Experience in teamwork with leaders in FinTech, Healthcare, Retail, Telecom, and others. Andersen cooperates with such businesses as Samsung, Siemens, Johnson & Johnson, BNP Paribas, Ryanair, Mercedes, TUI, Verivox, Allianz, T-Systems, etc..The opportunity to change the project and/or develop expertise in an interesting business domain.Job conditions – you can work both fully remotely and from the office or can choose a hybrid variant.Guarantee of professional, financial, and career growth! The company has introduced systems of mentoring and adaptation for each new employee.The opportunity to earn up to an additional 1,000 EUR per month, depending on the level of expertise, which will be included in the annual bonus, by participating in the company's activities.Access to the corporate training portal, where the entire knowledge base of the company is collected and which is constantly updated.Bright corporate life (parties / pizza days / PlayStation / fruits / coffee / snacks / movies).Certification compensation (AWS, PMP, etc).Referral program.English courses.Private health insurance and compensation for sports activities.

Join us!

Apply to vacancy

Похожие вакансии

  • Cybersecurity Engineer (Medical Device Project – Class II) Part-Time IRC269112

    GlobalLogic Київ, Київ, 22 часа назад
    ... a complementary Angular web application with a cloud-based backend.Job Summary:We are seeking a highly skilled and experienced Part-Time Security Engineer(e.g., 15-25 hours ... Strong understanding of web application security (OWASP Top 10), particularly with ...
    jobs.org.ua
  • Security Engineer

    Sisense Київ, Київ, 16 дней назад
    ... for a hands-on Security Operations Engineer to strengthen our detection and ... knowledge of cloud security monitoring tools and techniquesExperience analyzing endpoint, network, and application logs for anomalous eventsPractical understanding ...
    jobs.org.ua
  • Corporate Security Supervisor

    JTI час назад
    ... Goods Receipts (GR) related to security services and equipment.The Security Supervisor is crucial in incident ... the Management Team.Mentor new security staff and promote security awareness across departmentsCoordination and LiaisonServe ...
    jobs.jti.com
  • Senior Security Engineer

    Softjourn час назад
    ... to date with the latest security and technology developments;Maintain the security appliances and services;Provide an active role in defining security practices for new and ongoing ...
    softjourn.com
  • Application Security Engineer

    Andersen Ukraine час назад
    ... IT company Andersen invites a Application Security Engineer to join its team for ... payment platform.RequirementsExperience as an Application Security Engineer for 3-5 years. Proven ...
    people.andersenlab.com
  • Security Manager - Ukraine

    Tetra Tech Київ, Київ, 4 дня назад
    ... to reliable electricity, strengthens energy security, and powers resilient economies. We ... role in implementing safety and security arrangements for local and international ... bodies. Draft and organize security related documentation according to Tetra ...
    jobs.org.ua
  • Information Security Specialist

    Andersen Ukraine 6 дней назад
    ... teams to integrate security practices into the SDLC. Experience in an Application Security, Penetration Testing, or similar role. ... for all things application security. Experience with threat modelling and security architecture reviews to identify and ...
    people.andersenlab.com
  • Cloud Security Architect

    Deloitte Київ, Київ, 25 дней назад
    ... local and international cloud security projects where a diverse skillset, ... a team of seasoned cyber security professionals where inclusive leadership, continuous ... Cloud technologyKnowledge of information security principles and guidelines (including CIS, ...
    jobs.org.ua
  • Senior/Staff Application Security Analyst (Bangkok based, relocation provided)

    Agoda Київ, Київ, 13 дней назад
    ... , GCP, Azure, etc.)Experience performing security testing, e.g. code review and web application security testingFamiliarity with Gitlab, Defectdojo, JIRA, ... characteristics.We will keep your application on file so that we ...
    jobs.org.ua
  • Humanitarian Access and Risk Officer

    63517UAH
    Medecins du Monde Миколаївська область, Миколаїв, день назад
    ... the implementation of safety and security policies at the base level. ... and in accordance with MDM’s security protocols. Operating under the direct ... . 5. Briefings, Trainings & Awareness Deliver security briefings to new staff, visitors, ...
    jobs.org.ua
  • Humanitarian Access and Risk Officer

    63517UAH
    Medecins du Monde Миколаївська область, Миколаїв, месяц назад
    ... the implementation of safety and security policies at the base level. ... and in accordance with MDM’s security protocols. Operating under the direct ... . 5. Briefings, Trainings & Awareness Deliver security briefings to new staff, visitors, ...
    jobs.org.ua
  • Information Security Engineer

    Andersen Ukraine час назад
    ... IT company Andersen invites Information Security Engineer to join our team and ... a progression from analyst to engineer for 5+ years. Strong hands-on skills in malware analysis, digital forensics, and offensive security. Certifications such as GCIH, GCFA, ...
    people.andersenlab.com
  • Security Operations Engineer – Identify and Access Management (IAM) Specialist

    Agoda Київ, Київ, 3 дня назад
    ... for identity automation, access policies, application integrations, lifecycle management, and security features like MFA and adaptive ... Azure AD in hybrid environments Application Security Collaborate with application owners to onboard new apps ...
    jobs.org.ua
  • Security Operations Engineer – Identify and Access Management (IAM) Specialist

    Agoda Київ, Київ, месяц назад
    ... for identity automation, access policies, application integrations, lifecycle management, and security features like MFA and adaptive ... Azure AD in hybrid environments Application Security Collaborate with application owners to onboard new apps ...
    jobs.org.ua
  • InfoSec (DevSecOps) Engineer

    LoopMe , Lviv, 15 дней назад
    ... Level Specialist to enhance our security posture and ensure our systems ... strong background in information security, familiarity with cloud environments like ... e.g., CISSP, CISM, CompTIA Security+, GCP Security Engineer) are a plus.  Excellent communication ...
    ua.talent.com
  • Security Systems Engineer in Security Team (#1010)

    Namecheap , , 11 дней назад
    ... Relevant certifications (e.g., CompTIA Security+, GSEC) Master’s degree in Computer ... involved into:  Configure and maintain security systems Participate in the design ... from various sources Perform regular security audits (e.g., workstation updates, ...
    ua.talent.com
  • Information Security Risk Manager

    JTI час назад
    ... now  Learn more: jti.comInformation Security Risk ManagerPosition Purpose:We are seeking an experienced Information Security Risk Manager to play a ... cross-functional teams and communicating security concepts to non-technical stakeholders. ...
    jobs.jti.com
  • Information Security ConsultantTernopil, Ivano-Frankivsk, Lviv, Uzhhorod, Chernivtsi, UkraineSecurity Department.

    Eleks , Ivano-Frankivsk, 11 дней назад
    ... motivated expert in the Information Security domain with good communication skills. ... master’s degree in information security or similar English – upper-intermediate ( ... for information Perform comprehensive security assessments to identify potential risks ...
    ua.talent.com
  • Cyber SOC Incident Response Manager

    JTI час назад
    ... resolution.Follow IR security standards, properly document IR actions ... stage according to security standards.Collect forensics malicious payloads, ... improve the overall security posture.Knowledge managementMonitor Security Industry trends on new threats ...
    jobs.jti.com
  • Cyber SOC Incident Response Analyst

    JTI час назад
    ... defense handling low and medium security incidents.Escalate to the Tier ... on reporting activitiesKnowledge management:Monitor Security Industry trends on new threats ... year of experience in Information Security or 2 years of experience ...
    jobs.jti.com
  • Junior InfoSec (DevSecOps) Engineer

    LoopMe , Lviv, 16 дней назад
    ... Unix administration. Understanding of information security principles (encryption, authentication, access control) ... motivation to grow in information security. Benefits: Competitive compensation package Flexible ...
    ua.talent.com
  • Security Engineer (Middle/Senior) ID35384

    AgileEngine , , 12 дней назад
    ... leaders in areas like application development and AI ML, and ... experience in Detection and Response, Application Security, or Infrastructure Security, preferably at a startup;- Knowledge ... and most productive.Your application doesnt end here To unlock ...
    ua.talent.com
  • Security Engineer (Middle/Senior) ID35384

    AgileEngine , Vovchynets', 12 дней назад
    ... leaders in areas like application development and AI ML, and ... experience in Detection and Response, Application Security, or Infrastructure Security, preferably at a startup;- Knowledge ... and most productive.Your application doesnt end here To unlock ...
    ua.talent.com
  • Application Engineer

    Linde Gas Ukraine , Dnipro, 18 дней назад
    ... applications and technologies LindeAs the Application Sales Engineer Manufacturing your target will be ... to identify those chances, match them with the best fitting gas, application or technology and develop ...
    ua.talent.com
  • Senior Security Management

    Customertimes Poland, Portugal, Croatia, Bosnia and Herzegovina, Montenegro, Serbia, Romania, Bulgaria, North Macedonia, Albania, Greece, Cyprus, Remote час назад
    ... and other relevant SAP security tools. Proven track record in ... . Participate actively in SAP security audits, implementing necessary security measures and addressing any deficiencies ... teams to implement SAP security strategies that align with business ...
    customertimes.com
  • Security Engineer (Middle/Senior) ID35384

    AgileEngine , Kharkiv, месяц назад
    ... experience in Detection and Response, Application Security, or Infrastructure Security, preferably at a startup;- Knowledge ... happiest and most productive.Your application doesnt end here To unlock ...
    ua.talent.com
  • Security Engineer (Middle/Senior) ID35384

    AgileEngine , Kyiv, месяц назад
    ... experience in Detection and Response, Application Security, or Infrastructure Security, preferably at a startup;- Knowledge ...
    ua.talent.com
  • Systems Engineer (MS Intune, Ukraine)

    Capgemini Engineering Київ, Київ, месяц назад
    ... a skilled and proactive Systems Engineer to join the clients team. ... device enrollment, policy configuration, and application deploymentImplement security policies and configurations to ensure ...
    jobs.org.ua
  • Cyber Security Engineer on-site in Oman

    Andersen Ukraine час назад
    ... company Andersen invites a Cyber Security Engineer to join its team for ... for each project phase. Developing security policies for the Super App ... Detection and Response (EDR), and Application Security practices (SAST DAST). Familiarity with ...
    people.andersenlab.com
  • Cloud Security Specialist

    Span Київ, Київ, 23 дня назад
    ... value of the implementation of security technologiesCollaborate with cloud solution architects ... enterprise solutions with the Microsoft security platformDevelop the technical documentation of ...
    jobs.org.ua
  • IAG App Authorization Manager

    JTI час назад
    ... to gather and align application access management details with JTI ... access management across JTIs application portfolio.As the IAG Apps ... and process workflow design, security systems, in the areas of security application support, and customer service in ...
    jobs.jti.com
  • DevOps Engineer

    JTI час назад
    ... . Cooperate with internal Databases, Network Security, Service bus & Data  teams in ... Cloud, DevOps, Networking, Storage, SRE & Security. Experience in technical quality control ... . In case of processing your application under the employee referral program, ...
    jobs.jti.com
  • Middle Test Automation Engineer

    SoftServe , , 11 дней назад
    ... client is a US-based security and networking company that helps people connect securely and confidently on any device, to any application, anywhere, anytime. We leverage the ...
    ua.talent.com
  • Senior JavaScript Developer

    Ciklum , , 5 дней назад
    ... , analysts and product owners, we engineer technology that redefines industries and ... frontline to develop and refine security agents for macOS, Windows, and ... Deployment: Hands-on experience with application deployment patterns and tools (Docker) ...
    ua.talent.com
  • Middle/Senior Systems Engineer (MS Intune)

    Capgemini Engineering Рівненська область, Рівне, 2 дня назад
    ... a skilled and proactive Systems Engineer to join the clients team. ... device enrollment, configuration profiles, and application deploymentImplement and manage security policies, compliance rules, and configuration ...
    jobs.org.ua
  • Head of Security Department

    Andersen Ukraine 6 дней назад
    ... monitoring of the companys cyber-security.Comply with compliance certification and ... leaks, implementation of SOC, ensuring security of End-points, etc..Ability ...
    people.andersenlab.com
  • IT Security Administrator

    Auditdata , Kyiv, 20 дней назад
    ... + years experience in system networking security administration positions or similar Hands- ... 365 (Exchange Online, SharePoint, Teams, security policies) Experience with Zabbix (setup, ... .   We look forward to your application (please submit your CV in ...
    ua.talent.com
  • IT Security Administrator

    Auditdata , Kyiv, 20 дней назад
    ... + years experience in system networking security administration positions or similar Hands- ... 365 (Exchange Online, SharePoint, Teams, security policies) Experience with Zabbix (setup, ... .   We look forward to your application (please submit your CV in ...
    ua.talent.com
  • IT Security Administrator

    Auditdata , Kyiv, 20 дней назад
    ... + years experience in system networking security administration positions or similar Hands- ... 365 (Exchange Online, SharePoint, Teams, security policies) Experience with Zabbix (setup, ... .   We look forward to your application (please submit your CV in ...
    ua.talent.com

Карточка вакансии:

  • Должность Application Security Engineer
  • Размещено: 2025-07-02 21:04:58
  • Город Ukraine
  • Зарплата:
  • Компания: Andersen