18 лютого 2022

Application Security Engineer (вакансія неактивна)


Необхідні навички

• Experience of 1-3 years in the Application Security / Penetration Testing domain.
• Technical / academic education or hands-on experience in one of the following domains: Computer Science, Software Engineering, Information Systems
o Advantage: Hands-on DevOps / Software Development experience
• Familiarity with software development processes in teams / companies
o Advantage: Working in a software development company
• Familiarity with Application Security standards and frameworks (OWASP, NIST, etc.)
o Advantage: Previous experience researching / implementing application security tools (SAST, Web Application Scanners / DAST, Open Source Analysis, etc.)
• Decent English level (speaking, writing, reading), good people skills and positive approach


• Work with R&D teams to assure the implementation of Secure Development Lifecycle
o Serve as the focal point for developers, QA engineers and managers for security questions
o Perform hands-on security activities, such as code review, design review, threat modeling
o Review results from security tools such as security static analysis, open source security, security dynamic analysis, etc
o Provide input for Security Management on progress of security KPI of each team
• Evaluate surrounding security aspects of the development process such as CI/CD processes
o Mapping the elements in the CI/CD process (code projects, builds, etc) and prioritize based on code sensitivity
o Evaluate the hardening of CI/CD components such as code repositories, build servers, artifact servers, etc
o Review the security of processes around deployment (separation of production and non production components, access reviews, etc)
• Research and suggest solutions and new tools to solve security problems in new topics
o Enhance automation around SDLC and CI/CD Security
o Suggest tools to help fellow Application Security team members to work at sacle
• Align teams on recent security standards and policies
o Train Playtech employees regarding security topics
o Build new policies based on new cases which were not documented before
• Support application security domain during audits and regulations (ISO27001, PCI, GDPR, etc).

Про проект

Playtech, a leading gaming software company, is seeking a curious, capable and hands-on Application Security Engineer, who will work with software and development teams to ensure secure development lifecycle practices such as security reviews in design and code, security requirements analysis, testing the software for security purposes and vulnerability management.