hero image

Application Security / Product Security Engineer

Description

We are looking for an Application Security / Product Security Engineer to support and improve security processes across the software development lifecycle (SDLC) and CI/CD environments for our client. In this role, you will work closely with engineering teams to help implement and maintain security controls, improve vulnerability management processes, support compliance initiatives, and strengthen secure development practices across modern software delivery pipelines.

office remoteEuropean UnionUkraine

Requirements

  • 2–5 years of experience in Application Security, Product Security, DevSecOps, Security Operations, or related cybersecurity roles
  • General understanding of Secure SDLC and application security principles
  • Experience working with security tools or processes related to vulnerability management, CI/CD security, or dependency/security scanning
  • Familiarity with Jira or similar ticketing/tracking systems
  • Understanding of common application security risks and vulnerabilities
  • Ability to document processes and communicate effectively with technical teams
  • English skills sufficient for technical communication and participation in project discussions

Nice to have

  • Hands-on experience with SCA tools such as FOSSA, Snyk, Mend, Black Duck, or similar
  • Familiarity with open-source license compliance processes
  • Experience with secret detection tools, pre-commit hooks, or CI/CD secret scanning
  • Experience integrating security controls into GitHub Actions or other CI/CD platforms
  • Familiarity with vulnerability remediation workflows and SLA tracking
  • Experience with asset inventory tools such as NetBox
  • Experience supporting audits or compliance initiatives (ISO 27001, SOC 2, etc.)
  • Familiarity with SAST, DAST, container scanning, or cloud security tooling
  • Experience working in cloud-native or Kubernetes environments

Responsibilities

  • Support Software Composition Analysis (SCA) processes and open-source license compliance activities
  • Help implement and maintain secret detection practices, including pre-commit hooks and CI/CD secret scanning
  • Participate in vulnerability management activities: vulnerability scanning, triage and prioritization, Jira ticket tracking, remediation follow-up and SLA monitoring
  • Collaborate with engineering teams to improve Secure SDLC and CI/CD security practices
  • Support security tooling integrations within CI/CD pipelines (e.g., GitHub Actions)
  • Maintain security-related documentation and assist with audit/compliance activities
  • Contribute to asset inventory and security governance processes
  • Work with development and infrastructure teams to improve overall security posture

We offer

  • Projects for such clients as PayPal, Wargaming, Xerox, Philips, Adidas and Toyota;
  • Competitive compensation that depends on your qualification and skills
  • Career development system with clear skill qualifications
  • Flexible working hours aligned to your schedule
  • Options to work remotely
  • Corporate medical insurance covering services of private and public medical centers
  • English courses online
  • Corporate parties and events for employees and their children
  • Internal conferences, workshops and meetups for learning and experience sharing
  • Gym membership compensation
  • 5 days of paid sick leave per year with no obligation to submit a sick-leave certificate

Any questions?

Apply for

Apply for

Application Security / Product Security Engineer

Apply by filling in the form beside or sending your CV to hh@itransition.com

By clicking the button Agree & send I give my consent to Itransition Group to process my personal data in accordance with Recruitment Privacy Statement for the purpose of potential employment, internship and future career opportunities.

The total size of attachments should not exceed 10 MB.

Allowed types:

jpg

jpeg

png

gif

doc

docx

ppt

pptx

pdf

txt

rtf

odt

ods

odg

odp

xls

xlsx

xlxs

vcf

vcard

key

rar

zip

7z

gz

gzip

tar