Application Security Engineer at Rocket.Chat

Rocket.Chat logo
Rocket.Chat

Application Security Engineer

Remote

Contractor

#Engineering

#Penetration Testing

#Security

#Application Security

#Python

#JavaScript

Rocket.Chat is looking for a Application Security Engineer

Sign up to unlock quick summaries and profile fit assessments

Job Title: Application Security Engineer

Level: Mid Level

Working Hours: Full Time (40h/Week)

Contract: Contractor (PJ)

Location: Remote [LATAM]

Your Team šŸ‘„

You will report to our Head of Security and join the Security team. On TheOrg you can view the complete structure of our organisation, including information about every team member, hiring managers and the size of each department.

Your Responsibilities āœļøĀ 

You will be responsible for implementing and maintaining robust security measures to safeguard our organization's critical assets from cyber threats. You will play a crucial role in identifying and fixing security vulnerabilities, automating processes, and proactively implementing security controls to protect our applications.

Mandatory Hard Skills šŸŽÆ

  • Previous experience with penetration testing of at least 2 of the following: web applications, APIs, cloud environments, mobile applications, or Active Directory;
  • Knowledge of security assessment tools (Nessus, OpenVAS, Trivy, Semgrep, Github Advanced Security (Dependabot, CodeQL, and Secrets Scanning), etc.);
  • Understanding of application security issues, best practices, and standards such as OWASP Top 10, OWASP ASVS, OWASP WSTG, OWASP Cheat Sheet Series, and the like;
  • Some proficiency in languages such as Python, Go, Powershell, Bash or Javascript;
  • Intermediate to advanced English.

Desirable Hard Skills šŸ’•Ā 

  • Ability to perform security reviews on Javascript code;
  • Familiarity with a cloud service provider such as AWS, Azure, GCP, or DigitalOcean;
  • Familiarity with security on containerization and orchestrators (Docker, Kubernetes, etc..) can be a nice-to-have;
  • Familiarity with threat modelling and related standards and methodologies (DREAD, STRIDE, PASTA, etc.);
  • Understanding of compliance frameworks like ISO 27001, SOC 2, or GDPR;
  • Relevant certifications such as OSCP, OSWE, CBBH, CPTS, BSCP, PNPT, DCPT, CRTO, CRTP, eJPT, eWPT, and the like are nice-to-have but not mandatory.

Soft Skills ✨

  • Ability to collaborate with development teams to ensure that applications are designed with security in mind;
  • Excellent problem-solving and troubleshooting skills;
  • Effective communication and collaboration skills with both technical and non-technical stakeholders;
  • Strong analytical skills to identify root causes of complex issues and develop effective solutions;
  • Staying updated with emerging technologies and trends in the field is important for continuous learning.
  • Passion: Genuine enthusiasm for what you do and how it contributes to our company's mission;
  • Dream: Proactively seek out opportunities and challenges to achieve extraordinary results. If you're someone who takes initiative and is always striving to improve, you'll fit right in;
  • Own: Take ownership of your work, set high standards for yourself, and be accountable for outcomes demonstrating a strong sense of responsibility and commitment;Ā 
  • Trust: Recognizing the importance of trust and support and actively working towards a collaborative and inclusive workplace;
  • Share: Communicating openly and transparently, ensures clarity and honesty in interactions.Ā 

What You'll Do šŸ–„ļø

  • Update dependencies and change small pieces of code to fix vulnerabilities;
  • Triage and handle security issues through our vulnerability management process;
  • Support and conduct penetration testing across diverse environments, including web applications, APIs, and cloud platforms;
  • Perform threat modelling of new projects and features before and while they are being developed;
  • Conduct security architecture and code reviews in order to make recommendations on fixes and mitigation strategies;
  • Help write security documentation, especially in regards to application security;
  • Build security tooling and automation for internal use;
  • Promote security awareness and advocate for best practices within the organization;
  • Communicate risks and mitigations effectively.

Benefits ✨

  • Flexible Working Hours
  • Fully Remote
  • Unlimited Paid Time Off
  • Holidays and Vacation Days
  • Company Laptop and Headphone
  • Remote Benefit
  • iTalki
  • Courses and BooksĀ 
  • Stock Options
  • Multicultural environment with colleagues in over 26 countries
  • Vibrant Company Culture

Check out our handbook to dive into each of our awesome benefits!Ā At Rocket.Chat, we have tailored base pay ranges according to work locations. This approach ensures that we can competitively and consistently compensate our employees across different geographic markets.

About Rocket.Chat šŸš€

ā€Rocket.Chat is the world's largest open-source communications platform. Built for organizations needing more control over their communications, it enables collaboration between colleagues, partners, customers, communities, and even platforms without compromising data ownership, customizations, or integrations.

Tens of millions of users in over 150 countries and organizations such as Deutsche Bahn, the U.S. Navy and Credit Suisse trust Rocket.Chat every day to keep their communications completely private and secure. As Rocket.Chat we believe in reconnecting the world, one conversation at a time!Ā 

See yourself in that? So apply now! Check out our handbook for more information about our rocket.

Rocket.Chat logo

Rocket.Chat

3 views

0 applied

Company Size

101-250

Markets

Enterprise Software
Developer Tools

Social Media

Visit Rocket.Chat
Share this job
Copy Permalink
Open roles at Rocket.Chat
Rocket.Chat logo
Rocket.Chat

Senior Mobile Engineer

Remote

Full Time

#Engineering

#React Native

#TypeScript

#Mobile App Development

#UI UX Design

#Git

#GitHub

#APIs

#Agile Methodologies

Rocket.Chat logo
Rocket.Chat

Senior Fullstack Engineer

Remote

Full Time

#Engineering

#Node.Js

#JavaScript

#TypeScript

#AWS

#MongoDB

#RESTful APIs

#Docker

#Kubernetes

#Stream

#Grafana

Rocket.Chat logo
Rocket.Chat

Senior Security Engineer

Remote

Full Time

#Engineering

#JavaScript

#Architecture

#Security

#XSS

#CSRF

#OAuth

#SAML

#CSP

Discover similar jobs
Dijital-team-pty-ltd logo
Dijital-team-pty-ltd

Automation Engineer

Remote

Full Time

#IT

#Managed Services

#PowerShell

#Python

#Jinja

#BASH

#REST API

#JSON

#Git

#JavaScript

C
Candidly

Senior Infrastructure Engineer

Remote

Full Time

#Infrastructure Engineering

#Cloud Computing

#DevOps

#AWS

#Azure

#Kubernetes

#Docker

#IaC

#Python

#Linux

#Monitoring

#Security

PelotonInc logo
PelotonInc

Senior Software Engineer

Remote

Full Time

#Engineering

#Full Stack

#DevOps

#Docker

#Kubernetes

#AWS

#GCP

#Azure

#Flux

#Rancher

#Continuous Delivery

#Infrastructure

#Microservices

I
Ivanti

Associate Site Reliability Engineer

Remote

Full Time

#Site Reliability

#Cloud Operations

#DevOps

#Linux

#Windows

#Networking

#Kubernetes

#Docker

#Python

#Java

#AWS

#Azure

#Ansible

BioIntelliSense logo
BioIntelliSense

DevOps Engineer

Remote

Full Time

#Cloud

#DevOps

#Healthcare

#Terraform

#AWS

#Datadog

#Bitbucket Pipelines

#CircleCi

#Databricks

#Python

#Flutter

H
Hyperhug

QA Engineer

Remote

Full Time

#Game Development

#QA Testing

#Mobile

#Manual Testing

#TestRail

#Jira

#Android Studio

#XCode

#Unity

#Git

#Firebase

#Python

#C#

Tarmac Technologies logo
Tarmac Technologies

Python Django Backend Engineer

Remote

Full Time

#Technology

#Backend Development

#Tech

#Python

#Django

#RESTful API

#AWS

#Backend Engineering

H
HeyJobs

Graphic Design Creative Technology

Remote

Part Time

#Technology

#AI Tools

#Digital Marketing

#Engineering

#JavaScript

#Python

#Landing Pages

#Content

ProktaHRSolutions logo
ProktaHRSolutions

Senior Software Engineer - Network Services Orchestration

in flag
India

Remote

Full Time

#Automation

#Orchestration

#Technology

#Cisco

#Python

#Java

#Linux

#DevOps

N
Northflank.com

Backend Software Engineer

57k - 127k USD

Remote

Full Time

#Backend Engineering

#Cloud

#Microservices

#Go

#Python

#Node.Js

#SQL

#NoSQL

#RESTful APIs

#Docker

#Kubernetes

#AWS

N
NewPageSolutionsInc

Python Developer

Remote

Contractor

#Technology

#Digital Health

#Software Development

#Python

#AWS Lambda

#AWS ECS

#Automated Testing

#Agile Methodologies

#Terraform

#Drupal

#PHP

T
Teach For All

Head of AI Solutions & Engineering

Remote

Contractor

#AI

#Education

#Technology

#TypeScript

#Python

#REST APIs

#Git

#Design

#Google Cloud

#Business Analysis

Q
Quora

Staff Machine Learning Engineer

220k - 321k USD

Remote

Full Time

#Machine Learning

#Recommendation Systems

#Engineering

#Python

#C++

#Data Pipelines

#Model Training

#Algorithms

Ramp logo
Ramp

Security Engineer, Cloud

Remote

Full Time

#Cloud Security

#Security Engineering

#Fintech

#AWS

#Terraform

#Python

#Flask

#Infrastructure

#DevOps

DroneDeploy logo
DroneDeploy

Senior DevOps Engineer

Remote

Full Time

#DevOps

#Cloud Infrastructure

#MLOps

#Kubernetes

#Terraform

#Python

#Golang

#AWS

#Linux

#Observability

#GitHub Actions

Sevaa Group logo
Sevaa Group

Senior Drupal Developer

Remote

Contractor

#Drupal

#Engineering

#DevOps

#PHP

#Testing

#Responsive Design

#Security

H
HeyJobs

Graphic Design / Creative Technology

29k - 29k USD

Remote

Internship

#Technology

#AI Tools

#Digital Marketing

#Engineering

#Prototyping

#Automation

#JavaScript

#Python

N
Nomic Foundation

Senior Engineering Manager, Dev Tools

Remote

Full Time

#Ethereum

#Engineering

#People Management

#Technical Leadership

#Code Reviews

#Roadmap Planning

#Rust

#TypeScript

#Solidity

#Software Architecture

A
Able

Data Engineer

Remote

Full Time

#Data Engineering

#AI

#Software Development

#SQL

#Python

#Data Warehouses

#Airflow

#Data Modeling

#BI Tools

#Data Governance

Prosper logo
Prosper

Infrastructure Security Engineer

Remote

Full Time

#Fintech

#Cloud Security

#Information Security

#GCP

#Azure

#Terraform

#Wiz

#SIEM

#Python

Your dream job awaits.

Explore exciting opportunities, connect with top employers, and ignite your career.