Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Go @ 5
HTTP @ 3
JWT @ 2
Manual Testing
Networking @ 3
OAuth @ 2
Reporting @ 3
Rust @ 5
Security @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
At Nord Security, you will help secure applications and products used by millions of people worldwide. The role focuses on application security assessments, low-level security, secure architecture, vulnerability research, and security automation for mobile and desktop applications.
Responsibilities
- Conduct security reviews of application designs, source code, and third-party libraries.
- Perform application vulnerability assessments using automated tools and manual testing techniques, including SAST, DAST, SCA, and penetration testing.
- Collaborate with development teams to design secure architectures and implement security controls.
- Maintain security tools, scripts, and processes that support secure development.
- Monitor industry trends, zero-day vulnerabilities, and application security best practices.
- Develop scripts and security automation tools to improve application security testing.
- Design and deliver security engineering awareness and adoption training.
- Identify internal security gaps within products and the wider organization.
- Ensure mobile and desktop applications are sufficiently tested.
- Support internal and external audits.
Requirements
- Proven experience planning and conducting mobile and desktop application security assessments, testing, applying methodologies, and reporting vulnerabilities.
- Strong understanding of secure coding practices.
- Ability to perform manual security code audits.
- Proficiency in at least one low-level programming language, such as C, C++, Rust, or Go.
- Solid understanding of TCP, UDP, and HTTP networking protocols.
- Familiarity with debuggers such as GDB, LLDB, and WinDbg.
- Familiarity with reverse engineering tools such as Ghidra and IDA.
- Solid understanding of memory corruption issues, buffer overflows, and related vulnerability classes.
- Familiarity with authentication and authorization protocols, including OAuth, SAML, and JWT.
- Ability to use networking tools such as Wireshark and tcpdump.
- Ability to quickly learn new technologies and tools.
- Strong ownership, problem-solving, and investigation skills.
- Ability to build and maintain relationships and influence key stakeholders across the business.
- Contributions such as public CVEs, bug bounty recognition, open-source tools, or technical blogs are a bonus.
Benefits
- Extensive online and in-person training, access to Coursera and Skillshare, mentorship, and internal career opportunities.
- Extra vacation days, additional sick-leave days, and time off for special occasions and parenting.
- Premium private health insurance in Lithuania and Poland.
- Free subscriptions to Calm, Headspace, and Mindletic, plus resilience and mindfulness training and mental health events.
- In-house gyms, Multisport and Urban Sport cards, online workouts, and physical well-being support.
- Company workations, team buildings, company events, and milestone gifts.
- Flexible work-from-anywhere opportunities.
- Summer camps for children and parental flexibility.
- Access to Nord Security's Vilnius headquarters and facilities.
More jobs at Nord Security
DevOps Engineer - Mid - Threat Protection
Nord Security · Vilnius, Lithuania, Kaunas, Lithuania
EUR 43,200-69,600 per year
Retention Data Analyst
Nord Security · Vilnius, Lithuania, Kaunas, Lithuania
EUR 26,400-54,000 per year
Security Engineer – Mid-Senior – WebSec Team
Nord Security · Poland
PLN 206,400-396,000 per year
Site Reliability Engineer - Senior - NordVPN Apps
Nord Security · Poland
PLN 279,600-408,000 per year
Backend Engineer · Mid-Senior · Go · Coveron
Nord Security · Poland
PLN 237,600-400,800 per year
Similar jobs
Application Security Engineer · Mid-Senior · Low-Level
Nord Security · Vilnius, Lithuania, Kaunas, Lithuania
EUR 38,400-75,600 per year
Application Security Engineer - Mid-Senior - iOS
Nord Security · Poland
PLN 206,400-360,000 per year
Application Security Engineer · Mid-Senior · iOS
Nord Security · Vilnius, Lithuania, Kaunas, Lithuania
EUR 38,400-75,600 per year
Senior Software Engineer - Traffic and Networking
Nvidia · Santa Clara, United States
USD 224,000-431,200 per year
Staff Software Engineer - Site Defense
Reddit · United States
USD 217,000-303,900 per year
Security Engineer, Application Security
Sentry · San Francisco, United States
USD 155,000-400,000 per year
Security Engineer, Application Security
Sentry · Toronto, Canada
CAD 162,000-420,000 per year
Senior Software Engineer, Fleet Intelligence Agent Systems
Nvidia · Santa Clara, United States
USD 152,000-287,500 per year