This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Join our team as a SecOps Engineer, where you'll play a pivotal role in securing complex applications and infrastructure. This expert-level position focuses on vulnerability detection, secure code review, and proactive remediation, ensuring robust defenses against evolving threats. Collaborate remotely with like-minded professionals, leveraging your technical and communication skills in a dynamic, security-driven environment.
Job Responsibility:
Perform expert-level secure code reviews with a focus on OWASP Top 10 and CWE vulnerability classes
Identify, triage, and remediate application-layer vulnerabilities, including broken access control, IDOR, SQL injection, command injection, and deserialization flaws
Develop and maintain security automation tools using Python, GoLang, or JavaScript/TypeScript to streamline vulnerability detection and remediation processes
Conduct and document penetration tests, collaborating cross-functionally to drive remediation initiatives
Advise development teams on secure coding practices, bringing a proactive security mindset into the software lifecycle
Stay informed of emerging threats and incorporate best practices within the customer's environments
Communicate effectively through detailed written reports and verbal briefings, ensuring security findings are clearly understood and actionable
Requirements:
5+ years of hands-on experience in software engineering or security operations with a focus on application-layer security
Proficiency in Python, GoLang, Rust, JavaScript, or TypeScript
Demonstrated expertise in secure code review and professional penetration testing
Strong familiarity with OWASP Top 10, CWE, and modern vulnerability classes
Proven ability to detect, prioritize, and remediate vulnerabilities in production applications
Exceptional written and verbal communication skills, with a strong emphasis on clarity and detail
Fluent English and availability for at least 6+ hours overlap with Eastern Time
Nice to have:
Experience deploying, integrating, or maintaining vulnerability management platforms
Certifications such as OSCP, GIAC, or equivalent are advantageous
Background in cloud or container security practices