Application Security Engineer
Core
Application Security Engineer focusing on secure SDLC, application security reviews, and security monitoring for a travel reservation platform.
Role type
Senior IC Application Security Engineer
Builds
Secure web/API applications, CI/CD security controls, and security monitoring pipelines
Domain
Travel technology, Application Security, Cloud Infrastructure
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Application security, Secure SDLC, Web/API security, OWASP Top 10 mitigation, Threat modeling, SAST/DAST/SCA implementation, Python/Go/Java, AWS security (IAM, WAF, Kubernetes), SIEM/Detection engineering, Incident response, API security, Microservices security, AI-assisted security automation
Preferred skills
Pentesting, Bug bounty coordination, Terraform/IaC, Security tooling development, Security community contributions
Technologies
GitLab CI/CD, Elastic SIEM, AWS, Kubernetes, Terraform, Cursor, Tines
Responsibilities
Perform application security reviews, code reviews, and threat modeling; Implement and maintain CI/CD security controls (SAST, DAST, SCA); Assess and remediate vulnerabilities from scans and audits; Provide guidance on secure coding and architecture; Support security monitoring, alert tuning, and incident response; Participate in security on-call rotation
Seniority
Senior, hands-on IC
