freehire launches on Product Hunt on 26 August.

Follow →

Application Security Engineer / Penetration tester

Summary

You’ll test and secure web apps, APIs, and microservices by running penetration tests, code reviews, and triaging SAST/SCA findings to find and fix OWASP Top 10 and business-logic flaws before production.

Our client, Growe, is a leading business advisory and services group in iGaming and Entertainment. Сreators of strategies that work and solutions that scale. Combining strategic vision with hands-on expertise, Growe helps businesses navigate the fast-evolving industry, seize new opportunities, enter new markets, and achieve sustainable growth.
Perfect for those who aim to:
  • Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation;

  • Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production;

  • Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws;

  • Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorization, and business logic.

Experience you’ll need to bring:
  • 3 years of experience in Application Security, Product Security, or Penetration Testing;

  • Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner;

  • Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec;

  • Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment;

  • Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures;

  • Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC);

  • Ability to identify complex authorization bypasses, session management flaws, and business logic bugs;

  • Ability to read and analyze modern application code to spot security flaws (will be a plus);

  • Basic understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals (will be a plus);

  • Intermediate level of English (spoken and written).

It's a perfect match if you have those personal features:
  • Strong communication skills to effectively collaborate with engineering, product, and DevOps teams;

  • Result-oriented mindset;

  • Openness to learning.

Our clients offer competitive benefits to support your professional and personal growth, including:
  • Health & Wellness Focus;

  • Global Medical Coverage;

  • Growth Opportunities;

  • Benefits Programs (compensation for the gym/stomatology/psychological service & etc.);

  • Performance-Driven Rewards;

  • Dynamic Work Environment.

Apply, and let your growth journey begin.

What this application asks

greenhouse

First Name, Last Name, Email, Phone, Resume/CV, Cover Letter

  • What is your current location?
  • What is your Ukrainian proficiency level? choose one
  • What is your English proficiency level? choose one
  • What is your salary expectation in USD Gross (before taxes)?
  • What is your preferred messenger? Please provide your ID/username written answer
  • How did you hear about us? choose one

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available