yandex
cognism
Страна
Хорватия
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
SeniorУдалённоПолная занятость

Senior Application Security Engineer

Оценка ИИ

Отличная вакансия в лидирующей SaaS-компании с фокусом на современные технологии (AI/ML) и сильной инженерной культурой. Роль предлагает высокую степень автономии и возможность напрямую влиять на безопасность продукта мирового уровня.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует глубоких технических знаний в области безопасности веб-приложений, опыта работы с AI/ML рисками и сильных навыков влияния на инженерную культуру. Высокий порог входа обусловлен необходимостью иметь опыт разработки бэкенда и умением работать в быстрорастущем SaaS-окружении.

Анализ зарплаты

Медиана75 000 €
Рынок60 000 € – 95 000 €
Оценка ИИ

Указанная роль Senior уровня в европейском SaaS-секторе (с учетом локаций в Хорватии и Северной Македонии) предполагает конкурентную оплату. Рыночные оценки для удаленных или гибридных ролей такого уровня в этом регионе обычно находятся в диапазоне 60,000–90,000 евро в год.

Сопроводительное письмо

I am writing to express my strong interest in the Senior Application Security Engineer position at Cognism. With over 8 years of experience in application security and a deep background in backend development, I am particularly drawn to your mission of embedding security by design into AI-powered features and data pipelines. My expertise in AWS cloud security and integrating DevSecOps tools into CI/CD pipelines aligns perfectly with your goal of making the securest path the fastest path for engineers.

In my previous roles, I have successfully led threat modeling sessions and implemented automated security guardrails that reduced friction for development teams while significantly improving the overall security posture. I am a pragmatic problem solver who understands the balance between technical risk and business innovation. I am excited about the opportunity to bring my experience in securing SaaS platforms to Cognism and help scale your security maturity as the company continues its impressive growth.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в cognism уже сейчас

Присоединяйтесь к Cognism, чтобы внедрять инновационные стандарты безопасности в современные AI-продукты и защищать данные тысяч глобальных предприятий!

Описание вакансии

WHO ARE WE

Cognism is the leading provider of European B2B data and sales intelligence. Ambitious businesses of every size use our platform to discover, connect, and engage with qualified decision-makers faster and close more deals. Headquartered in London with global offices, Cognism’s contact data and contextual signals are trusted by thousands of revenue teams to eliminate the guesswork from prospecting.

THE ROLE 

The Senior Application Security Engineer is a key member of Cognism’s Information Security Team, reporting into the Application & Infrastructure Security Manager. Your mission is to embed security by design across our engineering and product organization by integrating modern application security practices throughout the full development lifecycle. We focus on building secure, scalable, and resilient systems while enabling the business to innovate quickly and safely. It is to drive a culture where the fastest path for our engineers is the securest path. 

You will work closely with Product, Engineering, Architecture, and Data teams to understand risks within our platform, including risks introduced by AI powered features, and ensure the right controls, guardrails, and security patterns are built into the product at its inception – all the while ensuring a balanced approach to the product experience that our thousands of large global enterprise customers use every day. 

This role is ideal for a senior IC who is technical, collaborative, and pragmatic, with the ability to influence engineering teams while driving hands on improvements to Cognism’s secure SDLC. 

KEY RESPONSIBILITIES 

Security by Design & Product Integration 

  • Partner with Product, Web and Data Engineering teams from the ideation stage to ensure security requirements are considered early in feature and model design.
  • Translate product and application risks into actionable security controls, making recommendations repeatable to build guardrails and guidance that product, design, and engineering teams can apply as they scale and build the products in the teams they own.
  • Help shape security acceptance criteria and guide engineering teams during design reviews and backlog planning.

Application Risk Assessment & AI Security 

  • Identify and assess application risks across Cognism’s SaaS platform, data processing pipelines, including emerging risks associated with AI/ML capabilities.
  • Contribute to AI feature reviews and participate in AI risk assessments to ensure responsible and secure use of models, in a way that balances the need to innovate and challenge the status quo in AI implementation.
  • Assess and pragmatically recommend mitigations for security risks in data pipelines, model-training workflows, feature stores, and ML systems, ensuring strong controls for data access, data lineage, model integrity, and protection of sensitive datasets.

Secure SDLC & DevSecOps Enablement 

  • Partner with our engineering and platform team to embed security guardrails into our software development lifecycle and agile engineering workflows.
  • Partner with engineering teams to integrate and optimize security tooling into CI/CD pipelines (SAST, SCA, DAST, container scanning, IaC scanning).
  • Drive automation and developer-friendly security processes that minimize friction and support rapid delivery.

Threat Modelling & Architecture Support 

  • Conduct and facilitate a self-serve, risk-driven approach to pragmatic threat modelling sessions for new features, services, and AI components.
  • Conduct threat modelling for data architectures, including ingestion, transformation, storage, streaming, and ML model deployment patterns, ensuring data confidentiality, integrity, and responsible use.
  • Provide hands-on application security guidance to engineering teams, helping them implement secure APIs, microservices, data flows, and integrations.
  • Maintain and expand Cognism’s secure coding standards, guidance, and reusable security patterns.

Application Security Testing & Engineering 

  • Perform hands-on security testing (manual and automated) for web applications, microservices, APIs, and cloud components.
  • Plan, coordinate, and oversee penetration tests, red team exercises, and third-party security assessments, ensuring findings are addressed and tracked.
  • Validate findings, assist with prioritization, and partner with engineering teams on remediation strategies.

Collaboration, Education & Influence 

  • Work directly with product squads, acting as a trusted advisor and embedded security partner. Take the time to understand what other teams are working on, what business priorities are, and partner with teams to recommend risk mitigations that balance risk with opportunity and that take into account the threat landscape.
  • Deliver security training, workshops, and guidance to improve engineering teams’ security maturity.Communicate security risk and tradeoffs clearly and constructively to technical and nontechnical stakeholders.

CORE COMPETENCIES 

  • Strong technical depth in application security, cloud security, and secure development.
  • Understanding of modern data stack components (e.g., data pipelines, feature stores) and the ability to collaborate effectively with data practitioners.
  • Deep understanding of communication protocols used for web development is a must-have.
  • Hands on experience with web application development, specifically for back-end development is a must-have competency.
  • Risk-Based Prioritization: Ability to distinguish between theoretical security risks and actual business threats, demonstrating a "risk-driven" rather than "compliance-driven" mindset. Comfortable balancing security risk with product and commercial realities.
  • Contextual Communication: Capacity to translate complex technical vulnerabilities into business-impact stories that resonate with non-technical stakeholders and product owners.
  • Collaborative Conflict Resolution: Proven track record of approaching engineering friction with transparency and pragmatism, balancing a firm stance on security with a deep care for the developer experience. Pragmatic problem solver with a growth mindset and bias toward action.
  • Architectural Empathy: Ability to put yourself in the position of your users (the engineers) to build security guardrails that are repeatable and embedded into existing workflows rather than added as hurdles.

EDUCATION & EXPERIENCE 

  • 5–10+ years of experience in Application Security, Product Security, or Security Engineering roles.
  • Strong experience securing cloud native SaaS platforms (AWS preferred) and Data pipelines.
  • Handson experience with secure coding, application testing, and CI/CD security automation.
  • Experience working closely with engineering and product teams in agile environments.
  • Familiarity with security frameworks such as OWASP ASVS, OWASP Top 10, NIST, ISO 27001/2.
  • Experience evaluating and securing AI/ML enabled features is a strong advantage.
  • Experience in SME or high-growth SaaS environments preferred.

WHY COGNISM

At Cognism, we’re not just building a company - we’re building an inclusive community of brilliant, diverse people who support, challenge, and inspire each other every day. If you’re looking for a place where your work truly makes an impact, you’re in the right spot!

Our values aren’t just words on a page—they guide how we work, how we treat each other, and how we grow together. They shape our culture, drive our success, and ensure that everyone feels valued, heard, and empowered to do their best work.

Here’s what we stand for:

🤝 We Own the Outcome Together.

🤓 We Deeply Understand our Customers.

🏆 We Celebrate Impact Wherever It Comes From.

At Cognism, we are committed to fostering an inclusive, diverse, and supportive workplace. We welcome applications from individuals typically underrepresented in tech, so if this role excites you but you’re unsure if you meet every requirement, we encourage you to apply!

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Application Security
  • AWS
  • SaaS
  • DevSecOps
  • CI/CD
  • SAST
  • DAST
  • SCA
  • Threat Modeling
  • Python
  • API Security
  • Microservices
  • OWASP
  • ISO 27001
  • AI Security
  • Machine Learning Security

Возможные вопросы на собеседовании

Проверка практического опыта интеграции безопасности в процесс разработки без замедления темпов выпуска продукта.

Расскажите о случае, когда вам удалось внедрить автоматизированный контроль безопасности в CI/CD пайплайн, который был положительно воспринят разработчиками. Как вы минимизировали количество ложных срабатываний?

Вакансия делает упор на безопасность AI-функций. Важно понять, как кандидат оценивает специфические риски моделей.

Какие специфические угрозы безопасности вы бы выделили при проектировании фичи на базе LLM (Large Language Models) и какие превентивные меры предложили бы внедрить на этапе дизайна?

Проверка навыков архитектурного анализа и умения находить компромиссы.

Опишите ваш подход к проведению сессий по моделированию угроз (Threat Modeling) для новой микросервисной архитектуры. Как вы приоритизируете выявленные риски для продуктовой команды?

Вакансия требует обязательного опыта в бэкенд-разработке.

Учитывая ваш опыт в бэкенд-разработке, какие наиболее распространенные уязвимости в бизнес-логике API вы встречали и как вы помогали инженерам исправлять их на уровне кода?

Оценка способности кандидата общаться с нетехническими стейкхолдерами.

Как вы будете аргументировать необходимость задержки релиза критически важной для бизнеса фичи из-за обнаруженной уязвимости перед Product-менеджером?

Похожие вакансии

SDOdev
380 000 ₽ – 500 000 ₽

Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)

SeniorУдалённоРоссия
Android · iOS · TCP/IP · HTTPS · Cryptography · MITM · Frida · Objection · Apktool · Jadx · Hopper · Smali · Hermes · Swift · Dart · Objective-C · C++ · Reverse Engineering · Cybersecurity
+19 навыков
MTS Web Services
250 000 ₽ – 300 000 ₽

Старший эксперт SIEM

SeniorВ офисеРоссия
SIEM · SoC · Linux · Windows · macOS · CCNA · LPIC-1 · Cybersecurity · Incident Response · Network Security
+10 навыков
Инфосистемы Джет
Не указана

Старший инженер внедрения SIEM

SeniorВ офисеРоссия
SIEM · SOAR · SGRC · ArcSight · MaxPatrol SIEM · FortiSIEM · QRadar · Splunk · Linux · Windows Server · Information Security
+11 навыков
HaaS Platform
от 400 000 ₽

Pentester (Offensive Security)

SeniorУдалённоРоссия
Pentesting · Linux · Python · Bash · Burp Suite · NMAP · OWASP Top 10 · Network Security · Red Team · Vulnerability Assessment · Go · JavaScript · C++
+13 навыков
СберАвто
200 000 ₽ – 350 000 ₽

Специалист по информационной безопасности

SeniorУдалённоРоссия
Fortinet · Palo Alto Networks · Check Point · ELK stack · Splunk · Cisco Prime · MaxPatrol · ArcSight · SolarWinds · VPN · PKI · OSPF · EIGRP · BGP · Kaspersky Security Center · Cortex XDR · Solar Dozor · Ansible · Terraform · Vulnerability Management · Patch Management
+21 навыков
СберАвто
Не указана

Application security specialist

SeniorУдалённоРоссия
SAST · DAST · IAST · RASP · SCA · WAF · SSDLC · DevSecOps · OWASP · Linux · Python · Go · Threat Modeling
+13 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

cognism
Страна
Хорватия