A

Senior Application Security Engineer

All European Careers • Bucharest Metropolitan Area
Remote Visa Sponsorship Relocation
Apply
AI Summary

Lead application security assessments and vulnerability management in Azure Cloud and DevOps environments. Perform SAST, DAST, SCA, penetration testing, and API security testing while advising development teams on secure coding practices. Requires +10 years experience, fluency in English, and expertise in OWASP Top 10, Azure Security, and security automation.

Key Highlights
Senior Application Security Engineer with +10 years experience
Full remote role with US Eastern Time alignment required
Expertise in SAST, DAST, SCA, penetration testing, and API security testing
Key Responsibilities
Perform and support application security assessments including SAST, DAST, SCA, penetration testing, API security testing, and manual security reviews
Conduct security testing of web, API, cloud, and enterprise applications using industry-standard tools and techniques
Validate findings, perform false-positive analysis, and execute retesting to verify remediation effectiveness
Identify and assess security weaknesses related to authentication, authorization, input validation, business logic, insecure design, and vulnerable components
Lead vulnerability management activities including identification, prioritization, remediation tracking, and reporting
Prioritize findings using business impact, exploitability, exposure, threat intelligence, and organizational risk criteria
Advise development teams on secure coding practices, remediation strategies, and secure SDLC implementation
Support integration of security testing and vulnerability management processes into CI/CD pipelines and DevSecOps practices
Support application security policies, standards, risk assessments, threat modeling, and secure design reviews
Assist with security compliance and audit-related activities
Develop security dashboards and metrics covering vulnerability trends, remediation SLAs, MTTR, and testing coverage
Communicate security risks and remediation priorities to technical and non-technical stakeholders
Technical Skills Required
Application Security Vulnerability Management Azure Cloud Azure DevOps
Benefits & Perks
Visa sponsorship available
Relocation package provided
Fully remote

Job Description


For our international customer, we are looking for a full remote Senior Application Security Engineer with +10 years of experience in Application Security, Security Testing, Vulnerability Management, or related cybersecurity disciplines in a Azure Cloud and Azure DevOps environment.


We are seeking an experienced Senior Application Security Engineer with strong expertise in application security testing, vulnerability management and DevSecOps advisory services. The successful candidate will lead security assessments, support vulnerability remediation efforts, advise development teams on secure software development practices, and contribute to application security governance, risk and compliance initiatives.


Candidates need to be flexible to work across time zones, including alignment with US Eastern Time where required. Candidates need to be fluent in English.




Tasks and responsibilities:

  • Perform and support application security assessments, including SAST, DAST, SCA, penetration testing, API security testing, and manual security reviews;
  • Conduct security testing of web, API, cloud, and enterprise applications using industry-standard tools and techniques;
  • Validate findings, perform false-positive analysis, and execute retesting to verify remediation effectiveness;
  • Identify and assess security weaknesses related to authentication, authorization, input validation, business logic, insecure design, and vulnerable components;
  • Lead vulnerability management activities, including identification, prioritization, remediation tracking, and reporting.
  • Prioritize findings using business impact, exploitability, exposure, threat intelligence, and organizational risk criteria.
  • Advise development teams on secure coding practices, remediation strategies, and secure SDLC implementation.
  • Support integration of security testing and vulnerability management processes into CI/CD pipelines and DevSecOps practices;
  • Support application security policies, standards, risk assessments, threat modeling, and secure design reviews;
  • Assist with security compliance and audit-related activities;
  • Develop security dashboards and metrics covering vulnerability trends, remediation SLAs, MTTR, and testing coverage.
  • Communicate security risks and remediation priorities to technical and non-technical stakeholders;



Profile:

  • Bachelor or Master degree;
  • Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Technology, or related discipline, or equivalent experience;
  • +10 years of experience in Application Security, Security Testing, Vulnerability Management, or related cybersecurity disciplines;
  • Strong hands-on experience with: SAST, DAST, SCA, Penetration Testing, API Security Testing, Manual Security Assessments, ...;
  • Extensive experience using Burp Suite for web and API security testing;
  • Hands-on experience with tools such as: Burp Suite, HCL AppScan, Sonatype Nexus IQ/Lifecycle, Fortify, SonarQube, Black Duck (or similar SCA tools), ...
  • Strong understanding of OWASP Top 10, CWE, OWASP ASVS, Secure SDLC, vulnerability management, and risk-based prioritization;
  • Experience collaborating with development teams to drive remediation and improve security maturity;
  • Strong written, verbal, and stakeholder communication skills;
  • Experience with Azure Cloud and Azure DevOps;
  • Experience with ServiceNow for vulnerability or incident management workflows;
  • Experience creating security dashboards and reports using Power BI;
  • Knowledge of NIST, MITRE ATT&CK, CIS Benchmarks, threat modeling, and application security governance practices;
  • Experience with AI-assisted security solutions, security automation, or agentic AI technologies;
  • Fluent in English;


Preferred Certifications

CISSP

CSSLP

GWAPT

GWEB

OSCP / OSWE

Security+

SSCP

Microsoft Azure Security Certifications (AZ-500 or equivalent)


Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Not Applicable

Alignerr

France
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

Bright Vision Technologies

United State

Data Security & DLP Analyst (AI Training)

Cyber Security
•
3h ago
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Not Applicable

Alignerr

United Kingdom

Subscribe our newsletter

New Things Will Always Update Regularly