About the job
At Veeam, we are the trusted leaders in Data and AI, dedicated to empowering organizations in understanding, securing, and fortifying their data and AI capabilities. As pioneers in data resilience and security posture management, we thrive at the intersection of identity, data, security, and AI risk management. Our headquarters in Seattle is complemented by a presence in over 30 countries, safeguarding the operations of more than 550,000 customers globally who rely on us to keep their businesses thriving. Join our journey as we move forward together, fostering growth, learning, and making significant contributions for some of the most renowned brands worldwide.
About the Role
As an Application Security Engineer specializing in Offensive Testing, you will spearhead penetration testing and Dynamic Application Security Testing (DAST) for our Veeam Data Cloud products. You will leverage Burp Suite and advanced web/API testing methodologies to uncover real, exploitable vulnerabilities, prioritize risks, and collaborate with engineering teams to ensure effective remediation.
Your role will also involve enhancing testing tools and processes to foster repeatability and assist teams in preventing recurring vulnerabilities, particularly in areas such as authentication, authorization, session management, and tenant isolation.
What You’ll Do
- Lead offensive testing initiatives: strategize testing scope, depth, and frequency; produce clear reports and reusable playbooks.
- Conduct extensive manual penetration testing: focus on web applications and APIs, emphasizing authentication/authorization, multi-tenant boundaries, and critical workflows; create realistic attack simulations by chaining issues.
- Employ Burp Suite daily: validate and reproduce findings utilizing advanced features; maintain repeatable scopes, macros, and authenticated flows.
- Execute and enhance DAST: perform authenticated scans, fine-tune processes to minimize false positives, and collaborate with CI/platform teams to scale scanning and manage credentials.
- Drive remediation efforts: generate high-quality reports, partner with engineers for fixes and retesting, and prevent regressions; ensure findings are categorized appropriately with designated severity and SLAs.
- Contribute to long-term security improvements: identify recurring patterns and aid teams in mitigating them through established standards, libraries, platform controls, and input in threat modeling/design reviews.

