Application Security Specialist
Role details
Job location
Tech stack
Job description
As a Junior Application Security Analyst in the Information Security team, you will help secure Checkout.com's software applications throughout the Secure Software Development Lifecycle (SSDLC). You will work closely with developers and product teams to integrate security early in the development process, identify and oversee the remediation of vulnerabilities, and ensure adherence to secure coding practices and application security standards. This role focuses on practical, hands-on security support while also growing your expertise in application security., SSDLC & Secure Coding
- Assist in integrating security controls into the SSDLC
- Support the creation and maintenance of secure coding guidelines (e.g., OWASP Top 10, CERT Secure Coding Standards)
Application Security Testing
- Run a Static Application Security Testing (SAST) and Software Composition Analysis (SCA) scans
- Conduct API security testing
- Support CI/CD pipelines to keep secure and effective integration
Threat Modeling & Application Security Analysis
- Participate in threat modeling sessions
- Document identified threats, assess risks and provide mitigation recommendations
- Assist in code and system reviews to analyse security in company's products
Vulnerability Management
- Triage and prioritise vulnerabilities from automated scans.
- Track, verify and ensure security flaws remediation.
- Assist to automate an AppSec pipelines
Collaboration & Awareness
- Collaborate with engineering teams to integrate security into product design and improve existing systems.
- Help deliver training and awareness on SSDLC best practices and secure coding.
- Contribute to security documentations.
Requirements
Do you have experience in TCP/IP?, * 1-3 years in application security, secure software development, or related IT/security role
- Understand basic network technologies and protocols (HTTP, TCP/IP, DNS and the OSI model)
- Understanding of common software vulnerabilities and their mitigations
- Basic programming experience in a popular language (e.g., Python, JavaScript, Golang)
- Understanding of CI/CD pipelines and DevSecOps principles.
- Basic understanding of AWS technologies and GitHub security features
- Strong attention to detail in documentation and assessments
Nice to haves:
- Familiarity with SAST/DAST/SCA tools and API security testing platforms
- Exposure to cloud-native application security (AWS, Azure, GCP)
- Understanding of container security (Docker, Kubernetes)
- Experience of participating in Capture The Flag (CTF) competitions
Key Competencies:
- Eager to learn and expand technical skills in application security
- Effective communicator with both technical and non-technical audiences
- Collaborative and pro-active problem solver