freehire launches on Product Hunt on 26 August.

Follow →

Full Stack Engineer

Summary

Build and ship secure fixes for web apps and APIs, using React/Angular and cloud tools while applying OWASP practices to remediate XSS, CSRF, SSRF, and secrets exposure.

Job Title: Security Full Stack Engineer (Application Security)

Experience: 5+ Years

Role Overview

We are hiring a Security Full Stack Engineer to join a high-impact engineering team focused on securing critical applications. This is a hands-on role where you will go beyond identifying vulnerabilities and take full ownership of fixing them within the codebase.

You will work closely with development and security teams to analyze, triage, and remediate vulnerabilities identified through penetration testing, SAST, DAST, and SCA tools. The role requires strong engineering capabilities combined with deep application security knowledge across modern backend and frontend technologies.

Key Responsibilities

1. Vulnerability Triage & Remediation

  • Analyze and validate vulnerabilities identified through SAST, DAST, and penetration testing
  • Perform root cause analysis and eliminate false positives
  • Write, test, and deploy secure code to remediate vulnerabilities including:
  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)
  • Server-Side Request Forgery (SSRF)
  • API security issues and secrets exposure
  • Manage and upgrade vulnerable third-party libraries and dependencies

2. Engineering & Collaboration

  • Design and document secure remediation solutions and coding practices
  • Work closely with development teams to implement and validate fixes
  • Coordinate with security teams for re-scans and penetration test retesting
  • Track remediation progress and maintain evidence in Jira

3. Governance & Reporting

  • Participate in remediation review meetings and governance discussions
  • Support preparation of security dashboards and reports
  • Maintain documentation for risk acceptance and exception handling

Key Requirements

Technical Skills

  • 5+ years of experience in software engineering with exposure to Application Security
  • Angular and/or React
  • Solid understanding of OWASP Top 10 and API Security Top 10
  • Experience working with SAST, DAST, and SCA tools (e.g., SonarQube, Checkmarx, Veracode, Snyk)
  • Knowledge of secure coding practices and vulnerability remediation techniques
  • Familiarity with cloud environments (AWS, Azure, or GCP) and secure architecture principles

Soft Skills

  • Strong analytical and problem-solving skills with attention to detail
  • Ability to perform deep root-cause analysis on complex issues
  • Excellent documentation and communication skills
  • Experience working in Agile environments with tools like Jira

Nice to Have

  • Relevant certifications such as CSSLP, CEH, or CASE
  • Experience with API gateways and microservices security

Why Join Us

  • Opportunity to work on high-impact, security-critical applications
  • Hands-on role with real engineering ownership
  • Collaborative environment bridging development and security

If you are passionate about secure coding and want to play a key role in strengthening application security from within, we’d love to hear from you.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available