Job details
AppSec guru
Application Security Engineer
Place of work
Remote
Employment type
Full-time, Part-time
Start
Immediately
Salary
from 3000 € gross / month + bonuses
Expanding your horizons
We are creating midPoint, the world’s leading open-source identity governance and administration (IGA) platform. Join our expert product engineering team and help to make security an enabler, not a barrier. Take ownership of penetration testing, vulnerability scanning, and secure code reviews to uncover risks before they matter. Be the guide who writes clear security advisories, helps developers fix vulnerabilities, and inspires secure coding practices across teams. Contribute to developer training and ensure our product lives up to the highest security standards. Use your abilities to work on a challenging yet exciting projects with an experienced team by your side from anywhere at any time. Apply today and become one of us!
What you will do
Evolveum attracts extraordinary people who want to do their best work. Make a real impact with the following responsibilities
- Perform and support security-focused code reviews and collaborate with developers on secure fixes
- Simulate real-world attacker techniques against our applications, APIs, and cloud environments
- Perform penetration tests of applications, APIs with default product configurations
- Act as the first line of defense for bug bounty submissions: triage reports, assess exploitability, and validate findings
- Conduct vulnerability scanning, analysis and risk prioritization od findings
- Support incident response by analysing reported security threats and proposing/implementing fixes
- Prepare security advisories and vulnerability disclosures
- Assist with threat modeling and risk assessment alongside security architect and CPO
- Stay updated with OWASP Top 10, NIST, secure coding, secure design practices and emerging threats, advising product development teams
- Integrate and maintain security testing tools into CI/CD pipelines (SAST/DAST, SCA, IaC scanning)
- Deliver developer training using insights from red team exercises, bug bounty findings, and real-world exploits
Skills and qualifications
Has what you’ve read so far already hooked you? Check if you have what it takes to excel at this job:
Experience
Proven experience in application security, penetration testing, or red teaming. Strong understanding of OWASP Top 10, common vulnerabilities (SQLi, XSS, CSRF, RCE, etc.) and relevant NIST frameworks. Solid software development background (Java, Python). Familiarity with cloud security testing and common misconfigurations. Experience with bug bounty platforms (e.g. HackerOne) or managing vulnerability disclosure programs. Excellent communication skills – ability to explain security issues to both technical and non-technical stakeholders
Software development
Experience with product development is an advantage
Problem solving
A creative approach towards problems and the ability to find a solution
Identity management
Familiarity with the identity management field is an advantage
Enthusiastic attitude
A passion for technology and willingness to understand the details of how things work
Education
A bachelor’s degree (and higher) and/or a proven track record
Language
English skills on the B2 level or higher
Independence
The ability to work independently, in a team, and with customers
what working at Evolveum brings
Benefits you will truly enjoy
Remote first
Work conveniently from home like most of our team, or join the rest of the colleagues in offices located in Bratislava and Košice.
Professional open source
Join one of the biggest open source projects in identity management & governance, and embrace the pure open source philosophy.
Your public profile
Build your own personal brand with pride and nothing to hide. Jump on our open source wave and develop midPoint openly with us.
Self-development
The space for your personal growth at Evolveum is limitless. Use it to the maximum and watch the team support you in doing so.
Freedom at work
It’s all in your hands: enjoy flexible working hours, no middle management watching over your shoulder, and even the software & hardware of your choice.
Room for pet projects
Do you have a vision you would like to work on in addition to your main responsibilities? Use the opportunity to allocate some of your work time to a pet project.
Meritocracy at its best
Count on merit in terms of competency, ability, and achievements when it comes to taking over responsibilities and your position on the team.
Pro-employee environment
Work at a company that values its employees and shows it through possible extra vacation time, financial bonuses, career growth opportunities, and educational resources.
Even a 4-day work week
Join a company that values your grind and results over time spent in front of your screen. Evolveum is open to negotiating your time availability to fit your needs.
Job salary
wage tier
3000 €
From in gross / month + bonuses