About the job
constructorknowledg is seeking an Application Security Engineer to join the team remotely from Istanbul, Turkey. The focus of this role is to strengthen web application security and promote secure development practices. The position requires hands-on experience in vulnerability testing and managing Software Bill of Materials (SBOM). Supporting secure Software Development Life Cycle (SDLC) processes and reducing software supply chain risks are central to this role.
Main responsibilities
- Conduct threat modeling and security architecture reviews for web applications and APIs.
- Perform manual and automated security testing throughout development and before releases.
- Design and implement security pipelines, including SAST and DAST, and integrate them into the SDLC.
- Oversee SBOM generation and usage during the SDLC.
- Collaborate with development teams to address and resolve vulnerabilities efficiently.
- Provide security guidance based on OWASP best practices and lead training for engineering teams.
- Monitor trends in application security threats, tools, and industry changes.
Location
This is a remote position based in Istanbul, Turkey.
