Growe is looking for a skilled Application Security Engineer and Penetration Tester to join our team. You will play a critical role in securing our web applications, microservices, and APIs by identifying vulnerabilities and ensuring robust security practices across our development lifecycle.
Key responsibilities
- Triage, validate, and prioritize security findings from SAST, SCA, and secret scanning tools while managing issues through to remediation.
- Conduct manual and tool-assisted code reviews to identify security vulnerabilities and logic flaws before code reaches production.
- Perform hands-on penetration testing of web applications and microservices to uncover security risks.
- Audit REST and GraphQL APIs with a focus on authentication, authorization, and business logic.
Requirements
- 2-4 years of experience in Application Security, Product Security, or Penetration Testing.
- Hands-on experience with security tools such as Burp Suite, Semgrep, Gitleaks, Trivy, and SQLmap.
- Deep understanding of OWASP Top 10 and OWASP API Security Top 10 vulnerabilities.
- Strong knowledge of identity protocols including OAuth 2.0, OIDC, JWT, and SAML.
- Ability to effectively collaborate with engineering, product, and DevOps teams.
What we offer
- A collaborative environment where team support is a core value.
- A result-oriented culture that focuses on achieving ambitious and clear goals.
- Opportunities to grow and evolve within a dynamic, change-ready organization.