Qualifications
We require candidates to have a minimum of 3 to 5 years of experience in application security, particularly focused on web applications and API security. Proficiency in at least one programming or scripting language such as Python, JavaScript, C#, or Go is essential. Familiarity with tools like OWASP ZAP, Burp Suite, or Snyk is highly desirable. Knowledge in secure coding practices, DevSecOps, and container security concepts will set you apart. Moreover, a strong understanding of CVE, CVSS, and vulnerability disclosure workflows is expected. Excellent command of business English is necessary, while knowledge of SBOM standards (CycloneDX, SPDX) and experience integrating SBOM tools into CI/CD pipelines would be advantageous.
About the job
constructorknowledg is looking for an Application Security Engineer to join the team remotely from Sofia, Bulgaria. The role centers on protecting web applications and helping the team build secure software from the ground up.
What you will do
- Test web applications to uncover vulnerabilities and highlight security risks.
- Oversee the Software Bill of Materials (SBOM), giving the team better insight and control over software components.
- Support secure practices throughout the Software Development Life Cycle (SDLC).
- Work to lower risks within the software supply chain.
Location
This position is remote, but requires residency in Sofia, Bulgaria.
About constructorknowledg
At constructorknowledg, we prioritize innovation and security in our software development processes. As a leader in our industry, we are dedicated to creating secure applications that protect both our organization and our clients.