Application Security Engineer role at Bonterra, responsible for supporting web application security and contributing to secure development practices. The role requires experience in application security, manual web application penetration testing, and securing modern web applications and APIs.
Requirements
- 3+ years of experience in application security, product security, or secure software development
- Experience with manual web application penetration testing
- Experience securing modern web applications and APIs
- Strong understanding of web application vulnerabilities, their root causes, and common remediation approaches
- Ability to review application source code as needed to support vulnerability triage and testing activities
- Proficiency in at least one programming language (e.g., Java, Python, JavaScript/TypeScript, C#, or Go)
- Experience working with CI/CD pipelines and modern development workflows
- Familiarity with security testing tools such as SAST, DAST, and SCA
- Strong communication skills and ability to work collaboratively with engineering teams
Benefits
- Comprehensive benefits package
- Bonus, incentives, equity, and comprehensive benefits program