The Application Security Engineer will perform security assessments, penetration testing, and threat modelling to secure internally developed applications. They will also collaborate with development and architecture teams to integrate security controls into the CI/CD pipeline and remediate identified vulnerabilities.
CCBill is an online payment services provider used by more than 30,000 websites globally that supports the needs of both new and established businesses in the e-commerce and online space.
We are seeking an Application Security Engineer to support the secure development of internally developed applications. The successful candidate will perform application security testing, code reviews, threat modelling and vulnerability assessments while supporting the integration of security controls into the software development lifecycle.
The role will work closely with the development, architecture and Information Security team to identify and remediate security risks and improve the overall security posture of applications.
Location: Serbia
Working Hours:Monday to Friday (40 hours); 1PM-9PM CET, fully remote
Key Job Requirements:
Application Security Testing:
Perform manual and automated security assessments of web applications and APIs.
Conduct application penetration testing to identify vulnerabilities, security weaknesses and configuration issues.
Document findings, remediation recommendations and risk ratings in clear technical reports.
Validate remediation activities through re-testing
Secure Development:
Participate in threat modelling exercises and security design reviews.
Perform security-focused source code reviews of internally developed applications.
Support developers in understanding and remediating identified vulnerabilities.
Promote secure coding practices and security awareness across development teams.
DevSecOps and Security Automation
Support the implementation and operation of security testing within CI/CD pipelines.
Assist with the deployment and tuning of:
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
Software Composition Analysis (SCA)
Secrets detection controls
Contribute to security automation initiatives using Jenkins, GitLab and Bitbucket.
Vulnerability Management
Track and manage vulnerabilities identified during security testing activities.
Work with development teams to prioritise and remediate findings.
Assist in assessing application security risks and recommending appropriate mitigation measures.
Collaboration
Work closely with development, architecture, infrastructure, and Information Security teams to improve application security.
Support security reviews prior to production deployments.
Contribute to the continuous improvement of application security standards, processes and procedures
Key Skills & Qualifications:
Required
Minimum 3 years of experience in application security, penetration testing, software development or a related information security role.
Experience performing web application security assessments and penetration testing.
Understanding of secure software development practices.
Experience reviewing source code and identifying common security vulnerabilities.
Strong knowledge of:
OWASP Top 10
CWE
NIST security guidance
Secure coding principles
Technical Skills
Knowledge of web technologies, APIs, databases and networking concepts.
Familiarity with programming languages such as:
Java
.NET/C#
Python
JavaScript
Perl
Understanding authentication, authorisation and session management concepts.
Tools
Experience with some of the following:
Burp Suite
OWASP ZAP
Nessus
Metasploit
Wireshark
SAST and DAST tools
CI/CD and DevSecOps
Exposure to:
Jenkins
GitLab
Bitbucket
Agile development environments
Personal Attributes
Strong analytical and problem-solving skills.
Effective verbal and written communication skills.
Ability to work collaboratively within cross-functional teams.
Willingness to learn and develop expertise in application security and DevSecOps practices.
Proactive, strategic thinker who can turn concepts into actionable plans.
Advocates security improvement initiatives while understanding business priorities and constraints.
Demonstrated experience in mentoring, coaching, and supporting the growth of a diverse and distributed team.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”