Jobs and Careers
QU

Senior Application Security Analyst

Quadcode
EMEA, worldwideRemotefull_timeVerifiedPosted 22 Jan 2024

About the role

About team

We are Quadcode, a fintech company excelling in financial brokerage activities and delivering advanced financial products to our global clientele. Our flagship product, an internal trading platform, is offered as a Software-as-a-Service (SaaS) solution to other brokers.

Now we are looking for Application security analyst in the Application Security team.

The team consists of 2 professionals: Application Security Analyst, and a Team Leader.

As an AppSec Analyst, you will play a key role in our team dedicated to the detection of incidents within both the applications and infrastructure of our company.

Tasks in the role

  • Tasks within the SDLC process: analysis of analyzer results, rule refinement, evaluation of their effectiveness;
  • Analysis of source code for applications in Go, C/C++, Python, SWIFT;
  • Conducting internal penetration tests;
  • Diving into the working of the process of containerized applications and the features of their implementations;
  • Preparing recommendations for identified vulnerabilities, taking into account the specifics of the technological stack and implementations.

Requirements

  • Experience with DAST (AFL, Fuzzing, Burp), including creating custom “farms”;
  • Experience in conducting pentests for virtualized infrastructure;
  • Experience in analyzing mobile applications;
  • Programming skills in any programming languages (C/C++, Java, Python, SWIFT, Go);
  • Experience with k8s, Docker;
  • Experience with traffic analyzers (Wireshark, etc.);
  • Experience in automating routine security processes;
  • Understanding of modern software development processes and practices: Agile, SDLC, DevOps, CI/CD;
  • Competent written and verbal communication skills (English B2, Russian B2+).

Would be an advantage

  • Successful participation in Bug Bounty programs;
  • CTF experience;
  • Familiarity with OWASP Testing Guide, OWASP Code Review Guide, OWASP Secure Coding Practices;
  • Experience working with and supporting HashiCorp Vault;
  • Experience with network vulnerability scanners (Nessus, XSpider, MaxPatrol, etc.).

We offer

  • Full-time remote work as a Service Provider in the following countries: Bulgaria, Georgia, Belarus, Hungary, Romania, Latvia, Lithuania, Moldova, Azerbaijan, Armenia, Kyrgyzstan, Greece, Croatia, Montenegro, Serbia, or Estonia (a residence permit is a must, except for Georgia)
  • Competitive remuneration;
  • Professional courses: from Coursera to Harvard;
  • Friendly, enjoyable and positive environment.

Currently, over 700 employees and service providers are stationed across our seven global offices located in the UK, Gibraltar, the UAE, the Bahamas, Australia, and the headquarters in Cyprus. By broadening its international presence, Quadcode not only offers a remote or hybrid work model but also presents a myriad of intriguing tasks and challenges for professionals like developers, market research analysts, and PR marketing specialists, among others.

    Join us today, and let's shape the future of fintech together!

    Note: All applications will be treated with strict confidence. We thank all applicants for their interest, however only those candidates selected for interviews will be contacted.

    #LI-JM1 #LI-Remote

    Apply for this role

    Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

    Apply Now →Generate Application Kit

    Free account required — sign up in 30s

    Company

    Quadcode

    View company profile →