Application Security Engineer
6 дней назад
This position is open exclusively for
Ukrainian residents within Ukraine
(preferably Kyiv or Lviv).
Cossack Labs is looking for an Application security engineer to join our Security team and work with us on building and breaking software. If you are interested in designing and building security controls, working hand-in-hand with software developers, performing security assessments, this may be the position for you.
We are ready to invest time in your education if you are prepared to work diligently and responsibly. Alongside technical skills, we'll teach you leadership, time management, business context, and how to keep improving cybersecurity despite the ever-increasing entropy of the world.
Responsibilities:
- Perform security assessment and review of code and behavior of systems (web, API, backends).
- Participate in SSDLC for our products and our customers' products. Explain risks & threats, work together with developers to select security controls that would improve security without restricting usability/performance.
- Take part in organisation security practices and work with business owners (risk assessment, craft policies for organisations, guide companies for more secure future).
- Stay up to date with emerging security threats, vulnerabilities, and controls (read articles and papers, follow CVE updates, understand how threat landscape is changing, understand how to apply described ideas, read NIST guidelines).
- Dive into application security, infrastructure security, cloud and on-prem infrastructures, dedicated hardware, IoT security, ML security, and weird stuff beyond casual imagination with our team of skilled engineers. See example of our work.
- Share your work as conference talks, blogposts (see Security autotests post), contribute to open source standards like OWASP.
Requirements:
- 2+ years as an application security engineer or similar position.
- Experience in performing security assessment for web applications.
- Experience in selecting or designing security controls in a technically diverse environment.
- Be familiar with application security verification and software maturity frameworks: OWASP SAMM, OWASP ASVS.
- Understanding SSDLC (OWASP SSDLC, NIST SSDF).
- Communication skills: you will communicate about security technical topics with both technical and non-technical audiences (C-level managers, developers, product owners).
- An overall understanding of what information security is, how real-world risks and threats affect the choice of security controls.
- Experience in popular security tools required for the job, or ability to learn them quickly (Burp Suite, network analysers, various SAST and DAST, dependency and vulnerability scanners).
Nice to have:
- A certain area of expertise and deep interest: web, mobile, IoT, infrastructure — an area where you have "seen things" and ready to share experience.
- Basic knowledge in cryptography: understanding the differences between symmetric and asymmetric cryptography, hashing, KDF.
- Understanding security standards and methodologies (NIST, ISO, CMMI, SOC).
- Understanding risk management and threat modelling (NIST RMF, FAIR, STRIDE, MITRE ATT&CK).
- Practical experience in scripting languages: Python or Bash.
Our hiring process:
- Resume review — 1-5 business days.
- Test task — estimated time 3-4 hours.
- Introductory meeting with the Head of security engineering.
- Technical interview with several team members.
- Offer discussion.
What's in it for you?
- A sense of meaning and responsibility for those who seek purpose — we're building "invisible texture of modern civilization"—bits of infrastructure finance, power grids, healthcare rely on, and we are trusted with very challenging aspects of it.
- Competitive compensation with a flexible bonus scheme.
- Hybrid work model: this position allows for a combination of in-office and remote work as needed.
- UK, EU and USA clients.
- Working at the crossroads of ML security, cryptographic protocol support, hardware protection, reverse-resilient mobile app development, and securing web apps for millions of users.
- Public track record in the open-source aspect of our products.
- Conferences, books, courses — we encourage learning and sharing with the community. Our team members share a lot in talks, workshops, and blog posts.
- Paid vacation — 21 business days per year.
- Paid sick leaves.
-
Microsoft Cloud Security Engineer
6 дней назад
Киев, Киев, Украина New Era Technology Полный рабочий деньJoin New Era Technology, where People First is at the heart of everything we do. With a global team of over 4,500 professionals, we're committed to creating a workplace where everyone feels valued, empowered, and inspired to grow. Our mission is to securely connect people, places, and information with end-to-end technology solutions at scale.At New Era,...
-
Security Pre-Sales Engineer
2 недель назад
Киев, Киев, Украина Netwave LLC Полный рабочий деньNetwave —високопрофесійна команда ентузіастів в інфраструктурних технічних напрямках (Мережа, Обчислення, Інформаційна Безпека і Керування Даними), яка через впровадження інтеграційних проєктів і...
-
Safety and Security Coordinator
1 неделя назад
Киев, Киев, Украина Geneva Call Полный рабочий деньEngaging the world's armed groups and de facto or provisional authorities in complex situations, Geneva Call's staff is a force for humanity, respect and hope. We employ a highly motivated and dedicated staff from diverse backgrounds and nationalities. We offer a unique working environment in a challenging field. If you're skilled and passionate, we would...
-
Field Security Associate
2 недель назад
Киев, Киев, Украина UNDP Careers Полный рабочий день 30 000 ₴ - 60 000 ₴ в годJob DescriptionDiversity, Equity and Inclusion are core principles at UNDP: we value diversity as an expression of the multiplicity of nations and cultures where we operate, we foster inclusion as a way of ensuring all personnel are empowered to contribute to our mission, and we ensure equity and fairness in all our actions. Taking a 'leave no one behind'...
-
Senior Security Officer
2 недель назад
Киев, Киев, Украина UNOPS Полный рабочий деньApplication period 21-Oct-2025 to 11-Nov-2025Functional Responsibilities:Advisory and technicalOperationsPersonnel Capacity on Safety and SecurityTeam managementKnowledge Building and Knowledge SharingAdvisory and TechnicalMaintain awareness of the changes in the security environment, timely reacting and advising the Country Director, office management team,...
-
Network Security Engineer
1 неделя назад
Киев, Киев, Украина Evoplay Полный рабочий деньEvoplay — найбільша еко-система продуктових проєктів в Україні, яка пропонує прогресивні розробки та комплексні рішення для ігрової онлайн-індустрії.Ми не стоїмо на місці і постійно ростемо. Наразі...
-
Senior Back-End Security Developer
2 недель назад
Киев, Киев, Украина Sigma Software Полный рабочий день 80 000 $ - 120 000 $ в годCompany Description We're looking for a Senior Back-end Engineer with a strong background in security to help build a next-generation confidential computing system from the ground up.You'll design cryptographic infrastructure, develop Back-end services and APIs, and shape the core platform architecture. Working with HSMs, TEEs, and enterprise-grade...
-
Unified Support Engineer
1 неделя назад
Киев, Киев, Украина Cloudlinux Полный рабочий деньWe are currently seeking an experienced Support Engineer with a strong focus on security. The ideal candidate will possess a solid background in working with web application firewalls (WAF), mitigating DDoS attacks, detecting and handling malicious code, and having experience with popular Content Management Systems (CMS) and other relevant security...
-
Unified Support Engineer
1 неделя назад
Киев, Киев, Украина Cloudlinux Полный рабочий деньWe are currently seeking an experienced Support Engineer with a strong focus on security. The ideal candidate will possess a solid background in working with web application firewalls (WAF), mitigating DDoS attacks, detecting and handling malicious code, and having experience with popular Content Management Systems (CMS) and other relevant security...
-
Technologist Engineer, Security Firmware Engineering
2 дней назад
Киев, Киев, Украина Sandisk Полный рабочий деньCompany Description Sandisk understands how people and businesses consume data and we relentlessly innovate to deliver solutions that enable today's needs and tomorrow's next big ideas. With a rich history of groundbreaking innovations in Flash and advanced memory technologies, our solutions have become the beating heart of the digital world we're living in...