NE

Senior/Staff Application Security Engineer

Nebius

ILremote countryPosted Feb 17, 2025
Posting intelligenceMay be filled, listed long ago

Skills

javascriptpythoncicdjavakubernetesgoml

About the role

About Nebius:

Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.

Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.

Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

Application Security

The team is responsible for the security of Nebius's main public offerings : Compute, VPC, Managed K8s, Marketplace, Managed Soperator, and others. This includes building out the Secure SDLC, threat modeling, and vulnerability management platforms.

The Role

We are looking for an Senior/Staff Application Security Engineer who will ensure the security of our software by identifying and mitigating vulnerabilities, implementing best security practices, and collaborating with development teams. The ideal candidate will have a strong background in secure coding, threat modeling and building Secure SDLC.

What you will do

Build and maintain Application Security Posture Management (ASPM) at the Company scale.

Automate and support SAST, SCA tools, etc as part of CI/CD pipelines.

Improving SAST, secrets detection rules. Keeping false positive rate low.

Identify, analyze, and remediate application security vulnerabilities.

Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC).

Develop and maintain secure coding guidelines for development teams.

Conduct, run threat modeling and risk assessments for new and existing applications.

Provide development teams with instruments that facilitate security-related work like threat modelling, vulnerability detection, etc.

Stay updated on the latest security threats, vulnerabilities, and mitigation techniques.

Serve as an application security subject matter expert to other teams.

What we look for

6+ years of experience in application security.

Strong knowledge of common application security risks (e.g. OWASP Top 10) and how to mitigate them.

Experience with secure coding practices in languages such as Python, Go, Java, or JavaScript.

Proficiency in a common programming language (such as Go or Python) with a willingness to learn Go, if necessary.

Hands-on experience with security testing tools (Burp Suite, ZAP, Semgrep, etc.).

Understanding of authentication protocols like SAML or OIDC.

Experience in conducting threat-modeling sessions.

Bonus points

Confidence in presenting your ideas and opinions in a manner that can be challenged, while responding well to feedback.

Experience in designing, building, and maintaining security automation.

Experience in translating compliance and regulation requirements into technical specifications.

Experience in exploiting vulnerabilities in web applications, Linux kernels, containers, and networks.

Security certifications such as OSCP or OSWE.

We conduct coding interviews as part of the process.

#LI-CP1

Benefits & Perks:

Competitive compensation

Career growth and learning opportunities

Flexibility and ownership

Collaborative and innovative culture

Opportunity to work on impactful AI projects

International environment and talented teams

What's it like to work at Nebius:

Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI

Equal Opportunity Statement:

Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.

If you need accommodations during the application process, please let us know.

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on Nebius's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for Application Security Engineer roles in Israel varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Application Security Engineer hub for Israel medians across recent openings.

You never touch the form - the application is filled and submitted for you on Nebius's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.