Back to the board

Application Security Engineer (Remote in Bulgaria, Germany, Italy, Serbia, Turkey)

100% remote Flexible hours Hiring now

Our mission

Constructor’s mission is to enable all educational organisations to provide high-quality digital education to 10x people with 10x efficiency.

With strong expertise in machine intelligence and data science, Constructor’s all-in-one platform for education and research addresses today’s pressing educational challenges: access inequality, tech clutter, and low engagement of students.

Please send your resume in English only.

We are seeking an Application Security Engineer with a strong background in web application security design, secure development practices, and vulnerability testing. This role also requires practical experience with Software Bill of Materials (SBOM) management and implementation, contributing to our secure SDLC and software supply chain risk reduction efforts.

Key Responsibilities

  • Perform threat modeling, security architecture review, and design analysis for web applications and APIs.
  • Conduct manual and automated security testing during development and pre-release stages.
  • Design and implement security pipelines (including SAST and DAST) and integrate them into the SDLC process.
  • Implement and manage SBOM generation and consumption processes across the SDLC.
  • Collaborate with development teams to ensure timely remediation of identified vulnerabilities.
  • Maintain security guidance aligned with OWASP best practices and provide trainings for development teams.
  • Stay current with evolving application security threats, tools, and industry developments.

Qualifications

  • 3–5 years of experience in application security, with a focus on web applications and API security.
  • Good knowledge of at least one scripting or programming language (e.g., Python, JavaScript, C#, or Go).
  • Experience with tools like OWASP ZAP, Burp Suite, Snyk, or similar.
  • Familiarity with secure coding, DevSecOps, and container security concepts.
  • Strong understanding of CVE, CVSS, and vulnerability disclosure workflows.
  • Excellent command of business English.
  • Preferred Qualifications:
  • Knowledge of SBOM standards (CycloneDX, SPDX) and experience integrating SBOM tooling into CI/CD pipelines.
  • Knowledge of software composition analysis (SCA) tools.

What We Offer

  • Choice of work equipment (e.g., laptop, monitor, etc.)
  • English classes (iTalki – $130 monthly)
  • ⏰ Flexible schedule (we usually work between 09:00/10:00 and 18:00/19:00 CET or EET)
  • Newborn bonus (€500 per child)
  • Patent remuneration
  • Paid leave
  • ‍ Remote work in locations without our offices
  • Hybrid work in locations with offices (2 days in-office, 3 days remote)

Constructor fosters equal opportunity for people of all backgrounds and identities. We are led by a gender-balanced board committed to building a diverse and inclusive organisation where everyone can become their best self. We do not discriminate based on age, disability, gender identity, sexual orientation, ethnicity, race, religion or belief, parental and family status, or other protected characteristics. We welcome applications from women, men and non-binary candidates of all ethnicities and socio-economic backgrounds. We encourage people belonging to underrepresented groups to apply.

Apply To This Job

Keep exploring

Application Security Engineer (Remote in Bulgaria, Germany, Italy, Serbia, Turkey)

100% remote Flexible hours

Application Security Engineer (Remote in Bulgaria, Germany, Italy, Serbia, Turkey)

100% remote Flexible hours

Field Clinical Representative - Boston

100% remote Flexible hours

Business Assistant

100% remote Flexible hours

AI & Data Science Director

100% remote Flexible hours

Senior Manager, Quality Assurance

100% remote Flexible hours

VP Media, Marketing Services

100% remote Flexible hours

Operations Support Specialist

100% remote Flexible hours

Staff Platform Engineer

100% remote Flexible hours

Director, Technology Delivery

100% remote Flexible hours

Experienced Full Stack Customer Service Specialist – Remote Operations and Crisis Management

100% remote Flexible hours

Experienced Virtual Customer Care Professional – Delivering Exceptional Service from Home

100% remote Flexible hours

Internship- Health Analytics Research

100% remote Flexible hours

Earn Extra Income – Part Time – Online

100% remote Flexible hours

Entry-Level Freight Dispatcher Opportunity (Remote) – Earn $114,400-$156,000/Year & $2,200-$3,000/Week

100% remote Flexible hours

Experienced Home-based Customer Service Representative/Data Entry Specialist – Travel Industry

100% remote Flexible hours

Kubernetes Operations Engineer

100% remote Flexible hours

Senior Principal Software Engineer – Enterprise Technology – Customer Support at arenaflex

100% remote Flexible hours

Senior Financial Analyst | Remote

100% remote Flexible hours

Experienced Entry-Level Remote Customer Chat Support Specialist for Exceptional Client Service Delivery

100% remote Flexible hours