Nebius

Senior/Staff Application Security Engineer

Lead · Удалённо · Израиль · Английский B2

Навыки

  • Burp Suite
  • CI/CD
  • Java
  • JavaScript
  • Kubernetes
  • Linux
  • Machine Learning
Ещё 7
  • OAuth / OIDC
  • OWASP
  • Ответственность за результат
  • Python
  • SAST / DAST
  • Жизненный цикл разработки
  • Управление уязвимостями

О компании и продукте

  • Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
  • Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
  • Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
  • The team is responsible for the security of Nebius's main public offerings : Compute, VPC, Managed K8s, Marketplace, Managed Soperator, and others. This includes building out the Secure SDLC , threat modeling, and vulnerability management platforms.

Задачи

  • Build and maintain Application Security Posture Management (ASPM) at the Company scale
  • Automate and support SAST, SCA tools, etc as part of CI/CD pipelines
  • Improving SAST, secrets detection rules. Keeping false positive rate low
  • Identify, analyze, and remediate application security vulnerabilities
  • Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC)
  • Develop and maintain secure coding guidelines for development teams
  • Conduct, run threat modeling and risk assessments for new and existing applications
  • Provide development teams with instruments that facilitate security-related work like threat modelling, vulnerability detection, etc
  • Stay updated on the latest security threats, vulnerabilities, and mitigation techniques
  • Serve as an application security subject matter expert to other teams

Требования

  • 6+ years of experience in application security
  • Strong knowledge of common application security risks (e.g. OWASP Top 10) and how to mitigate them
  • Experience with secure coding practices in languages such as Python, Go, Java, or JavaScript
  • Proficiency in a common programming language (such as Go or Python) with a willingness to learn Go, if necessary
  • Hands-on experience with security testing tools (Burp Suite, ZAP, Semgrep, etc.)
  • Understanding of authentication protocols like SAML or OIDC
  • Experience in conducting threat-modeling sessions

Будет плюсом

  • Confidence in presenting your ideas and opinions in a manner that can be challenged, while responding well to feedback
  • Experience in designing, building, and maintaining security automation
  • Experience in translating compliance and regulation requirements into technical specifications
  • Experience in exploiting vulnerabilities in web applications, Linux kernels, containers, and networks
  • Security certifications such as OSCP or OSWE
  • We conduct coding interviews as part of the process
  • Benefits & Perks
  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams
  • What's it like to work at Nebius
  • Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI

Паспорт вакансии

История публикации

Появилась в Вакандии26 дней
Перепубликациинетпубликовалась один раз
Проверяли на источникеВидели сегодня
Среди похожихНет данных22 из 30 · похожих вакансий слишком мало для сравнения

Откуда что взялось

Отмечено то, что вывели мы. Без пометки — значение назвал работодатель.

ГрейдLeadвычитано из текста вакансии
Формат работыУдалённо
ГеографияИзраильвычитано из текста вакансии
Зарплата≈ 18 833 USD в месяцнаша оценка, в вакансии не названа

Почему на этом месте в выдаче

Порядок выдачи объявлен контрактом: свежесть решает между днями, полнота и зарплата — внутри дня.

Полнота карточки1004 из 4 полей: грейд, формат, география, зарплата
Зарплата названа0вилки работодателя нет, показана наша оценка

Проверка Вакандии

Источники и свежесть

Тип источника
Карьерный сайт работодателя
Найдено публикаций
1
Посмотреть публикации и даты
  • greenhouseОсновная публикация · 2025-02-17

Работодатель

Nebius

50 активных вакансий · вилка работодателя указана в 23%

Открыть профиль компании

Безопасность

Отклик уходит на сайт источника

Вакандия показывает вакансию, но не отправляет отклик и не проверяет работодателя. Сам отклик вы оставляете на внешнем сайтеcareers.nebius.com.

Признаки мошенничества
  • Просят предоплату, «залог» или деньги за обучение и оборудование.
  • Требуют код из SMS, данные банковской карты или доступ к «Госуслугам».
  • Быстро уводят в мессенджер и торопят с решением.
  • Обещают большой доход без опыта и без деталей задач.

Настоящий работодатель не просит денег и платёжных данных до трудоустройства.

Продолжить поиск

Похожие вакансии

Причина сходства указана на каждой карточке

  1. Почему похожа: похожая специализация · тот же формат

    Spendesk

    Senior Security Engineer

    • Senior
    • Удалённо
    • Париж, Франция
    Подробнее