- Страна
- Нидерланды
Откликайтесь
на вакансии с ИИ

Application Security Engineer
Nebius — быстрорастущая компания в сфере AI-инфраструктуры с листингом на Nasdaq. Предложение включает гибкий график, работу с передовыми технологиями и сильную инженерную команду.
Сложность вакансии
Позиция требует глубоких знаний в области AppSec (OWASP, SAML/OIDC) и навыков программирования на Go или Python. Процесс отбора включает техническое интервью по кодингу, что повышает порог входа.
Анализ зарплаты
Зарплата в вакансии не указана, но для Senior/Middle AppSec инженеров в Европе (Амстердам/Берлин) рыночные предложения обычно находятся в диапазоне 75,000–110,000 евро в год. Nebius, как технологическая компания, ориентированная на AI, вероятно, предлагает конкурентоспособную оплату на уровне верхнего дециля рынка.
Сопроводительное письмо
I am writing to express my strong interest in the Application Security Engineer position at Nebius. With over four years of experience in application security and a deep understanding of the OWASP Top 10, I have a proven track record of integrating security into the SDLC and collaborating with development teams to build resilient software. My proficiency in Go and Python, combined with hands-on experience using tools like Burp Suite and Semgrep, aligns perfectly with the technical requirements of your Security Engineering Team.
I am particularly drawn to Nebius because of its leadership in the AI cloud infrastructure space. I have extensive experience in conducting threat modeling sessions and building security automation, which I believe will be instrumental in fortifying your platform's security posture. I am eager to bring my expertise in vulnerability remediation and secure coding practices to a dynamic environment that values innovation and initiative.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в nebius уже сейчас
Присоединяйтесь к Nebius и станьте ключевым экспертом по безопасности в авангарде развития AI-облаков!
Описание вакансии
Why work at NebiusNebius is leading a new era in cloud computing to serve the global AI economy. We create the tools and resources our customers need to solve real-world challenges and transform industries, without massive infrastructure costs or the need to build large in-house AI/ML teams. Our employees work at the cutting edge of AI cloud infrastructure alongside some of the most experienced and innovative leaders and engineers in the field.
Where we workHeadquartered in Amsterdam and listed on Nasdaq, Nebius has a global footprint with R&D hubs across Europe, North America, and Israel. The team of over 1400 employees includes more than 400 highly skilled engineers with deep expertise across hardware and software engineering, as well as an in-house AI R&D team.
The role
The Security Engineering Team within the Platform Security organization is responsible for the strategic selection, implementation, management, and optimization of cybersecurity tools and technologies that improve security capabilities of the organization's platform. This team is instrumental in fortifying the security posture, proactively identifying and responding to security threats, ensuring the resilience and protection of critical data, systems, and services.
We are looking for an Application Security Engineer who will ensure the security of our software by identifying and mitigating vulnerabilities, implementing best security practices, and collaborating with development teams. The ideal candidate will have a strong background in secure coding, vulnerability assessment, and penetration testing.
Your responsibilities will include:
- Build and maintain ASPM tools and their rules.
- Identify, analyze, and remediate application security vulnerabilities using tools like ASPM.
- Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC).
- Conduct manual and automated penetration testing of applications.
- Develop and maintain secure coding guidelines for development teams.
- Facilitate threat modeling and risk assessments on new and existing applications.
- Stay updated on the latest security threats, vulnerabilities, and mitigation techniques.
- Serve as an application security subject matter expert to other teams.
We expect you to have:
- 4+ years of experience in application security.
- Strong knowledge of common application security risks (e.g. OWASP Top 10) and how to mitigate them.
- Experience with secure coding practices in languages such as Python, Go, Java, or JavaScript.
- Proficiency in a common programming language (such as Go or Python) with a willingness to learn Go, if necessary.
- Hands-on experience with security testing tools (Burp Suite, ZAP, Semgrep, etc.).
- Understanding of authentication protocols like SAML or OIDC.
- Experience in conducting threat-modeling sessions.
- Strong problem-solving and analytical skills.
- Good written and verbal communication skills in English.
- Willingness to learn new things.
- Being comfortable working independently.
It would be an added bonus if you had:
- Confidence in presenting your ideas and opinions in a manner that can be challenged, while responding well to feedback.
- Experience in designing, building, and maintaining security automation.
- Experience in translating compliance and regulation requirements into technical specifications.
- Experience in exploiting vulnerabilities in web applications, Linux kernels, containers, and networks.
- Security certifications such as OSCP or OSWE.
We conduct coding interviews as part of the process.
What we offer
- Competitive salary and comprehensive benefits package.
- Opportunities for professional growth within Nebius.
- Flexible working arrangements.
- A dynamic and collaborative work environment that values initiative and innovation.
We’re growing and expanding our products every day. If you’re up to the challenge and are excited about AI and ML as much as we are, join us!
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- Python
- Go
- Java
- JavaScript
- Burp Suite
- OWASP Top 10
- SAML
- OIDC
- Semgrep
- ZAP
- Threat Modeling
- Penetration Testing
- ASPM
- SDLC
- Linux
- Docker
Возможные вопросы на собеседовании
Проверка практических навыков выявления уязвимостей в коде.
Расскажите о наиболее сложной уязвимости, которую вы обнаружили в ходе код-ревью или пентеста. Как вы помогли разработчикам её исправить?
Оценка умения интегрировать безопасность в процессы разработки.
Как бы вы организовали процесс внедрения ASPM-инструментов в существующий CI/CD пайплайн, чтобы не замедлить разработку?
Проверка навыков проектирования безопасных систем.
Проведите краткое моделирование угроз (Threat Modeling) для микросервиса, использующего OIDC для аутентификации. Какие векторы атак вы видите?
Оценка навыков программирования, критичных для автоматизации безопасности.
Напишите на Go или Python скрипт, который парсит вывод сканера безопасности и группирует уязвимости по критичности.
Проверка понимания специфики облачных платформ.
В чем заключаются основные риски безопасности при работе с контейнеризированными приложениями в облачной инфраструктуре?
Похожие вакансии
Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)
Исследователь безопасности Android
Эксперт по защите периметра (WAF)
DevOps-инженер/ИБ (devops engineer, information security)
Application Security Еngineer (AppSec)
Инженер по сетевой безопасности
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- Нидерланды