Job Description
- Security Analysis & Vulnerability Assessment: Conduct regular security assessments and penetration tests on Company products. Identify vulnerabilities and security gaps in existing applications and propose remediation solutions.
- Vulnerability Management: Lead the development and implementation of a comprehensive vulnerability management program. This includes continuous monitoring, analysis, and prioritization of vulnerabilities discovered in applications.
- Security Automation: Implement and maintain security tools and processes to automate the detection of security vulnerabilities. Integrate security tools into the CI/CD pipeline. Security tools to be considered (not limited to): Static code analysis (mainly Python and TypeScript); Dynamic code analysis and scanning for vulnerabilities using Burp Suite and OWASP ZAP; Software composition analysis.
- Establishing security controls in SDLC: Work with the development team to ensure secure coding practices are implemented. Provide training and guidance on security best practices and emerging threats. Conduct threat modeling, architecture review and consult development teams when making architecture decisions. Develop security requirements at the early stages of the product life cycle.
- Incident Response: Participate in the response to security incidents, including performing post-mortem analysis and recommending preventive solutions.
- Compliance and Standards: Ensure applications comply with industry standards and regulations such as OWASP, GDPR, SOC 2 and ISO 27001.
- Collaboration and Communication: Collaborate with cross-functional teams to promote a culture of security awareness. Communicate effectively with both technical and non-technical stakeholders.
- Understanding of architecture and working principles of modern applications.
- Experience with GCP cloud security.
- Strong knowledge of security principles, techniques, and protocols (e.g., OWASP Top 10, SSL/TLS, etc.).
- 5+ years of working experience as Application Security Engineer or in a similar position (Penetration testing, Red Team, Bug Bounty etc.).
- Strong knowledge of at least one scripting language (Python, PowerShell, bash).
- Excellent problem-solving and communication skills.
- English: B2 Upper-Intermediate
- Join one of the fastest-growing tech companies in North Africa
- Have a lasting impact on our company's culture
- Make a real impact on the world by helping us bring affordable financial and on-demand services to millions of Africans
- Work on some really hard technical challenges from identity infrastructure for Africans, digital payment networks to complex mapping and routing systems across the continent.
- We are the first Algerian startup to go through Y Combinator program and weβre backed by top investors including Unpopular Ventures, Rebel Fund and DainTree.VC
- Relevant information security certifications: CEH, OSCP, OSCE, LPT, etc.
- Knowledge of/experience with international information security standards and personal data protection standards: ISO 27XXX, PCI DSS, GDPR, etc.
- Knowledge of/experience with information security standards and frameworks: OAuth, WS-Security, X.509, SSL/TLS, etc.
- Bachelor's degree in Computer Science, Information Security, or related field.
- Experience in CTF or bug bounty programs.
- Knowledge of DevSecOps practices and tools.
- Experience in web or mobile apps development.
- Experience with Python applications security assessment.
Date Posted
05/15/2024
Views
33
Similar Jobs
Software Engineer C++ (Senior) - Apexver
Views in the last 30 days - 0
The role of a Senior Software Engineer at Apexver involves leading the design development and scaling of highperformance trading systems The position ...
View DetailsSoftware Engineer, iOS Core Product - Speechify, Inc.
Views in the last 30 days - 0
Speechify is a texttospeech product that has gained significant traction with over 50 million users worldwide The company has recently been recognized...
View DetailsThe SafetyWing Digital Nomad Residency - SafetyWing
Views in the last 30 days - 0
SafetyWing offers a digital nomad residency program with up to 4000 reimbursement for travel accommodation and work tools emphasizing mentorship commu...
View DetailsAI Trainer - Anuttacon
Views in the last 30 days - 0
The text describes a companys culture emphasizing creativity collaboration and impactful work It outlines a mission to create immersive virtual worlds...
View DetailsExecutive Assistant & Accountability Partner (Full‑Time, Remote, ET Hours) - N/A
Views in the last 30 days - 0
This job description outlines a remote Executive Assistant role requiring calendar management travel coordination family operations oversight and acco...
View DetailsInside Sales Contractor - Credit Wellness, LLC
Views in the last 30 days - 0
This job posting promotes a remote financial services sales role with competitive commissionbased compensation guaranteed training stipends and growth...
View Details