companyconstructorknowledg logo

Remote Application Security Engineer

constructorknowledgTurkey, Istanbul
Remote Full-time

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Unlock Your Potential

Generate Job-Optimized Resume

One Click And Our AI Optimizes Your Resume to Match The Job Description.

Is Your Resume Optimized For This Role?

Find Out If You're Highlighting The Right Skills And Fix What's Missing

Experience Level

Mid to Senior

Qualifications

Qualifications and Experience:3–5 years of experience in application security, particularly with a focus on web applications and API security. Proficient in at least one scripting or programming language (e.g., Python, JavaScript, C#, or Go). Hands-on experience with security tools such as OWASP ZAP, Burp Suite, Snyk, or similar. Understanding of secure coding practices, DevSecOps methodologies, and container security principles. Strong grasp of CVE, CVSS, and vulnerability disclosure processes. Fluent in business English. Preferred: Familiarity with SBOM standards (CycloneDX, SPDX) and experience with integrating SBOM tools into CI/CD pipelines. Knowledge of software composition analysis (SCA) tools is a plus.

About the job

constructorknowledg is seeking an Application Security Engineer to join the team remotely from Istanbul, Turkey. The focus of this role is to strengthen web application security and promote secure development practices. The position requires hands-on experience in vulnerability testing and managing Software Bill of Materials (SBOM). Supporting secure Software Development Life Cycle (SDLC) processes and reducing software supply chain risks are central to this role.

Main responsibilities

  • Conduct threat modeling and security architecture reviews for web applications and APIs.
  • Perform manual and automated security testing throughout development and before releases.
  • Design and implement security pipelines, including SAST and DAST, and integrate them into the SDLC.
  • Oversee SBOM generation and usage during the SDLC.
  • Collaborate with development teams to address and resolve vulnerabilities efficiently.
  • Provide security guidance based on OWASP best practices and lead training for engineering teams.
  • Monitor trends in application security threats, tools, and industry changes.

Location

This is a remote position based in Istanbul, Turkey.

About constructorknowledg

At constructorknowledg, we are committed to fostering a secure and innovative software development environment. As a leader in the technology sector, we prioritize security and quality in our software solutions, aiming to protect our clients and their data from emerging threats.

Similar jobs

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.