Astanahub Logo
Vacancies

Application Security Engineer

Published
Almaty Full-time Full-time

Main requirements

  • Experience in application security or product security roles
  • Hands-on experience with offensive security testing (e.g., Burp Suite, Nmap, Kali Linux)
  • Strong understanding of web and/or mobile security
  • Experience working with cloud-native applications (preferably AWS).
  • Solid knowledge of networking and operating systems
  • Experience with threat modelling and secure design practices
  • Basic programming knowledge (Python, JavaScript, Go, or similar)
  • Ability to identify and remediate common vulnerabilities (e.g., SQL injection, XSS)
  • Experience advising engineering teams on secure coding practices
  • Basic understanding of cloud environments and infrastructure concepts
  • Experience working in microservices-based architectures to mandatory

What you will do

  • Act as a security advocate for product owners and engineering teams
  • Perform web, backend, and mobile security assessments
  • Orchestrate and coordinate security testing activities including penetration testing
  • Participate in architecture and design discussions to ensure security is embedded from the start
  • Conduct threat modelling for new and existing features
  • Support and improve secure development practices across engineering teams
  • Integrate and enhance security tooling within CI/CD pipelines
  • Ensure adherence to Secure Development Lifecycle (SDLC) practices
  • Triaging findings from tools, bug bounty programs, and security reports
  • Provide guidance on secure coding practices and vulnerability remediation
  • Balance security requirements with engineering productivity
  • Collaborate with internal teams and external vendors on security initiatives
  • Additional responsibilities aligned to project needs:
  • Manage and reduce security backlog (e.g., reviews, threat models, pentest coordination)
  • Prevent backlog accumulation by efficiently handling incoming security requests
  • Correlate findings across multiple security tools and prioritize remediation efforts
  • Act as a security point of contact for specific product domains
  • Coordinate with external vendors for security testing and assessments
  • Provide practical and implementable security recommendations
  • Quickly onboard and contribute with minimal ramp-up in a fast-paced environment

What we offer

  • Full-time employment with official labor contract
  • Flexible work format: office, remote, or hybrid
  • Private health insurance
  • Paid vacation and sick leave
  • Access to internal and external learning platforms
  • Work equipment
  • Referral program with bonuses for recommending friends and former colleagues
Cover url
ЧК DataArt Kazakhstan Ltd.
Partners for Progress in Data and AI
IT-company
Job Type
Full-time
Type employment
Full-time
Required education level
Bachelor's degree
Direction
Information Technology
Work experience
At least 5 years
Salary
Not specified
search
All statuses
New
Viewed
Under review
Invitation
Confirm
Rejected
Name Work Experience Contacts Response date Notes Response status
reach

There are no responses yet

When someone responds to a vacancy, a list of candidates will appear here

69 Views
BugBounty WhatsApp Telegram
We use cookies to ensure the proper functioning of our website and for analytics. By continuing to use the website, you confirm your acceptance of the use of cookies. More
Share