This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Performing regular penetration testing and vulnerability assessments on internally developed and third-party web, iOS, and Android applications; Managing and integrating SAST, DAST, and IAST tooling into application security processes and engineering workflows; Contributing to the continuous improvement of the Secure Software Development Life Cycle (SSDLC) and DevSecOps pipelines; Conducting secure code reviews in close collaboration with software development teams; Producing clear and actionable security findings, providing remediation guidance, and tracking vulnerabilities through resolution; Monitoring the latest cybersecurity threats, zero-day vulnerabilities, and attack vectors to help strengthen proactive defense mechanisms; Collaborating with engineering and product teams to improve the security posture of applications across development, testing, and production environments; Applying AI-supported approaches in security research, vulnerability analysis, and workflow efficiency, while maintaining a strong understanding of secure and responsible AI usage in cybersecurity contexts
Job Responsibility:
Performing regular penetration testing and vulnerability assessments on internally developed and third-party web, iOS, and Android applications
Managing and integrating SAST, DAST, and IAST tooling into application security processes and engineering workflows
Contributing to the continuous improvement of the Secure Software Development Life Cycle (SSDLC) and DevSecOps pipelines
Conducting secure code reviews in close collaboration with software development teams
Producing clear and actionable security findings, providing remediation guidance, and tracking vulnerabilities through resolution
Monitoring the latest cybersecurity threats, zero-day vulnerabilities, and attack vectors to help strengthen proactive defense mechanisms
Collaborating with engineering and product teams to improve the security posture of applications across development, testing, and production environments
Applying AI-supported approaches in security research, vulnerability analysis, and workflow efficiency, while maintaining a strong understanding of secure and responsible AI usage in cybersecurity contexts
Requirements:
Bachelor's degree in Computer Science, Software Engineering, or a related field
Minimum 5 years of hands-on experience in web and mobile (iOS & Android) application security
Deep understanding of security standards and methodologies such as OWASP Top 10, OWASP Mobile Top 10, and SANS 25
Proficiency with application security testing and vulnerability analysis tools such as Burp Suite, Nessus, Acunetix, Fortify, Checkmarx, and MobSF
Strong knowledge of mobile application architectures, reverse engineering concepts, and secure coding principles
Experience contributing to SSDLC and integrating security into modern engineering and release processes
Familiarity with AI-assisted analysis and research workflows, and awareness of how AI can be applied in application security use cases
Excellent written and verbal communication skills in English
Strong analytical thinking, problem-solving capabilities, and a team-oriented mindset
Relevant certifications such as OSCP, OSWE, CEH, GWAPT, GMOB, eWPT, or eMAPT are highly preferred
Nice to have:
Relevant certifications such as OSCP, OSWE, CEH, GWAPT, GMOB, eWPT, or eMAPT are highly preferred