Application Security Engineer

Artestofficial β€” Armenia Β· Posted ~1 day ago

πŸ”“ Log in to save this job, tailor your resume & track your apply process β€” 7 days free, no card needed.

Log in to add to target list

Description

We build tech with art at the heart. Artest is a product-focused tech company based in Yerevan. We design products, build software systems, and grow a strong quality culture β€” with art at the heart of everything we do. We believe every professional should feel seen, inspired, and trusted. At Artest, we’ve created a space where ideas come to life through collaboration, passion, and precision. We invite a Senior Application Security Engineer to join our team. βœ… Responsibilities: βœ”οΈ Demonstrated ability to collaborate with other teams to achieve complex objectives. βœ”οΈ Responsible for security architecture design from cloud infrastructure to application through the implementation of "secure by design" principles. βœ”οΈ Collaborate with product managers, architects, and developers on the implementation of the security controls platform ecosystem and products. βœ”οΈ Proof security implementations within infrastructure and application deployment manifests and the CI/CD pipelines. βœ”οΈ Define required policies, controls, and capabilities for the protection of products and environments. βœ”οΈ Build and validate declarative threat models automation. βœ”οΈ Participate in engineering teams’ product planning cycles and committees. βœ”οΈ Oversee the product security aspects for migration of products and services from Data Center to public cloud, e.g., AWS. βœ”οΈ Serve as a trusted cyber security advisor to product and application teams. βœ… Requirements: βœ”οΈ Minimum of 3 years experience as an Application Security Engineer. βœ”οΈ Experience integrating security scanning/tooling into development pipeline. βœ”οΈ Experience in analyzing and securing microservices and applications developed using Javascript and Typescript. βœ”οΈ Experience with CI/CD pipelines (such as Gitlab, Jenkins) and infrastructure-as-a-code models (such as Terraform, Helm, or CloudFormation). βœ”οΈ Hands-on development experience in Python/shell scripting. βœ”οΈ Strong understanding of supply chain security, software integrity, and secure software delivery. βœ”οΈ Experience with docker and mesh technologies (such as ISTIO). βœ”οΈ Experience with architecture and security reviews, threat modeling and applications risk highly desired. βœ”οΈ Experience working with Agile methodologies. βœ”οΈ Knowledge of privacy laws and regulations, such as GDPR desired. βœ”οΈ Familiarity with industry regulations, frameworks, and practices. For example, PCI, ISO 27001, NIST, etc. βœ… PREFERRED QUALIFICATIONS: βœ”οΈ In-depth experience with architecting secure services on Kubernetes. βœ”οΈ Extensive experience with architecting secure services on AWS or on-prem data centers. βœ”οΈ Security-related professional certifications e.g., CISSP, CISM, CCSK, CCSP, CEH is highly desirable. βœ… We offer excellent benefits, including but not limited to: πŸ’» Learning and development opportunities and interesting, challenging tasks. ✈️ Relocation package (tickets, staying in a hotel for up to 2 weeks, and visa relocation support for our employees and their family members). πŸ“š Opportunity to develop language skills, with partial compensation for the cost of English/Spanish language classes (for localization purposes). πŸ₯ Private medical coverage. 🏝 Time for proper rest, with 20 non-business days per year and an additional 6 paid sick days. πŸ“ˆ Competitive remuneration level with annual review. 🀝 Team building activities.