Application Security Engineer (Remote in Bulgaria, Germany, Italy, Serbia, Turke

Remote Full-time
Our mission Constructor’s mission is to enable all educational organisations to provide high-quality digital education to 10x people with 10x efficiency. With strong expertise in machine intelligence and data science, Constructor’s all-in-one platform for education and research addresses today’s pressing educational challenges: access inequality, tech clutter, and low engagement of students. Our headquarters is located in Switzerland, and we also have legal entities in Germany, Bulgaria, Serbia, Turkey, and Singapore Please send your resume in English only. About the Role : We are seeking an Application Security Engineer with a strong background in web application security design, secure development practices, and vulnerability testing. This role also requires practical experience with Software Bill of Materials (SBOM) management and implementation, contributing to our secure SDLC and software supply chain risk reduction efforts. Key Responsibilities: · Perform threat modeling, security architecture review, and design analysis for web applications and APIs. · Conduct manual and automated security testing during development and pre-release stages. · Design and implement security pipelines (including SAST and DAST) and integrate them into the SDLC process. · Implement and manage SBOM generation and consumption processes across the SDLC. · Collaborate with development teams to ensure timely remediation of identified vulnerabilities. · Maintain security guidance aligned with OWASP best practices and provide trainings for development teams. · Stay current with evolving application security threats, tools, and industry developments. Qualifications: · 3–5 years of experience in application security, with a focus on web applications and API security. · Good knowledge of at least one scripting or programming language (e.g., Python, JavaScript, C#, or Go). · Experience with tools like OWASP ZAP, Burp Suite, Snyk, or similar. · Familiarity with secure coding, DevSecOps, and container security concepts. · Strong understanding of CVE, CVSS, and vulnerability disclosure workflows. · Excellent command of business English. Preferred Qualifications: · Knowledge of SBOM standards (CycloneDX, SPDX) and experience integrating SBOM tooling into CI/CD pipelines. · Knowledge of software composition analysis (SCA) tools. · Relevant certifications such as GWAPT, OSWE, or CSSLP. What We Offer Choice of work equipment (e.g., laptop, monitor, etc.) English classes (iTalki – $130 monthly) ⏰ Flexible schedule (we usually work between 09:00/10:00 and 18:00/19:00 CET or EET) Newborn bonus (€500 per child) Patent remuneration Paid leave ‍ Remote work in locations without our offices Hybrid work in locations with offices (2 days in-office, 3 days remote): Sofia: 59 G. M. Dimitrov Blvd., NV Tower, 8th floor, 1700 Belgrade: Makedonska 12, 11000 Belgrade, Serbia Istanbul: Rüzgarlı Bahçe Mah., Kavak Sok., Smart Plaza B Blok 31/B, 34805 Kavacık-Beykoz/İstanbul Sakarya: Esentepe Mh., Akademiyolu Sk., Teknoloji Geliştirme Bölgesi No. 10 D/206, Serdivan, Sakarya Izmir: Ege Üniversitesi Kampüsü, Erzene Mah., Ankara Cad., No:172/67, 35100 Bornova/İzmir Constructor fosters equal opportunity for people of all backgrounds and identities. We are led by a gender-balanced board committed to building a diverse and inclusive organisation where everyone can become their best self. We do not discriminate based on age, disability, gender identity, sexual orientation, ethnicity, race, religion or belief, parental and family status, or other protected characteristics. We welcome applications from women, men and non-binary candidates of all ethnicities and socio-economic backgrounds. We encourage people belonging to underrepresented groups to apply. Originally posted on Himalayas
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

**Experienced Data Entry Specialist – Remote Work Opportunity with arenaflex**

Remote Full-time

Senior Laboratory Technician

Remote Full-time

Entry-Level Virtual Data Entry Clerk - Remote Opportunity at blithequark

Remote Full-time

Vendor Manager

Remote Full-time

[Remote] Lead OT Solutions Engineer, Enterprise

Remote Full-time

Head of DTC Growth (CRO + Marketing + Revenue Leader)

Remote Full-time

Digital Data Analyst (Entry Level)

Remote Full-time

Experienced Customer Service Representative - Work from Home Opportunities with Amazon: Delivering Exceptional Service to a Global Customer Base

Remote Full-time

Experienced Data Entry Specialist – Remote Part-Time Opportunity with blithequark for Detail-Oriented Individuals

Remote Full-time

Paid Media Manager

Remote Full-time
← Back to Home