Application Security Engineer working with NordVPN's cybersecurity team. Conducting assessments and reviews to secure applications and systems against vulnerabilities.
Responsibilities
Conduct security reviews of application designs, source code, and third-party libraries;
Perform regular application vulnerability assessments using both automated tools and manual testing techniques (e.g., SAST, DAST, SCA, penetration testing);
Collaborate with development teams to design secure architectures and implement security controls;
Help maintain security tools, scripts, and processes to support secure development;
Stay current with industry trends, zero-day vulnerabilities, and best practices in application security;
Develop scripts and security automation tools to enhance application security testing processes;
Design and deliver training for security engineering awareness & adoption;
Actively look for internal security gaps within the product or organization overall;
Ensure mobile/desktop applications are sufficiently tested and support internal and external audits;
Requirements
Proven experience in mobile/desktop application security assessment planning, testing, methodologies, and vulnerability reporting;
Strong understanding of secure coding practices;
Ability to perform manual security code audit;
Proficiency in at least one low-level programming language (e.g. C, C++, Rust, Go).
Solid understanding of networking protocols such as TCP, UDP and the HTTP protocol;
Familiarity with debuggers (e.g. GDB, LLDB, WinDbg).
Familiarity with reverse engineering tools (e.g. Ghidra, IDA).
Solid understanding of memory corruption issues, buffer overflows and related vulnerability classes.
Familiarity with common authentication and authorization protocols (OAuth, SAML, JWT, etc.).
Ability to work with networking tools such as Wireshark and tcpdump.
Ability to quickly assimilate new technologies and tools;
Sense of ownership with strong problem-solving and investigation skills;
Ability to build and maintain relationships, influence key stakeholders across the business;
Bonus points for community contributions like public CVEs, bug bounty recognition, open-source tools, blogs, etc.
Senior Databricks Application Engineer designing and building data applications on Databricks. Focused on Python applications, integrations, and supporting CI/CD practices in a collaborative environment.
Field Application Engineer providing technical evaluations and pre - sales support in video surveillance solutions. Collaborating with sales teams and conducting system designs for secure solutions in various industries.
Senior Application Engineer designing and deploying software applications supporting business processes at National Interstate Insurance. Collaborating across teams to enhance user experience and system integration.
Memory Design Application Engineer providing specialized technical support in memory compiler generation for Intel Foundry Services. Collaborating on integration challenges and driving quality improvements in memory design methodologies.
Lead Application Security Engineer at Nasdaq designing and implementing robust IT solutions and security assessments for cloud and on - premise applications. Collaborating on Google cloud technology projects with a focus on security.
Integration Engineer in SAP systems to enhance global engineering processes. Collaborating with international teams to integrate SAP with modern engineering tools.
Intern working on RF testing applications and solutions at LitePoint, collaborating with Field Applications Team and customers. Gaining hands - on experience in RF testing, debugging, and development.
Field Application Engineer developing application solutions in the semiconductor industry. Collaborating with customers and teams, leading projects to ensure optimal performance and satisfaction.
Field Application Engineer managing customer solutions in semiconductor industry. Collaborating on productivity and efficiency for various clients with a focus on training and support.