Security Application Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+12 more
Job description
A leading global sports betting and gaming company, significant operations in Sofia’s tech hub, and a focus on innovative customer-facing platforms seeks a Security Application Analyst.Es esencial asegurarse de que cumple con los requisitos como solicitante para este puesto; por favor, lea atentamente la información a continuación.This role bridges software development and cybersecurity, ideal for developers transitioning to secure coding practices.Role OverviewJoin the Sofia cybersecurity team to perform security assessments on customer-facing applications.Focus on vulnerability management, code reviews, and compliance in a regulated betting environment.Collaborate with developers to embed security in Agile workflows, minimizing risks across Java, .NET, Python, and PHP stacks.Key ResponsibilitiesConduct SAST, DAST, and penetration testing using tools like Checkmarx, Burp Suite, OWASP ZAP, and Snyk.Review code, manage SCA for third-party libraries, and integrate security into CI/CD pipelines with Jenkins or Azure DevOps.Investigate incidents, support SOC operations, and ensure PCI DSS/ISO compliance while educating developers on OWASP Top 10 risks.Required Qualifications3+ years in software development (Java, .NET, Python, PHP) with transition to application security.Proficiency in SAST/DAST tools (SonarQube, Veracode, Semgrep), WAF configuration, and runtime monitoring (Contrast Security).Knowledge of secure frameworks (Spring, ASP.NET), Unix systems, and regulated industry standards.Preferred SkillsExperience with secrets detection, IaC security, and container scanning in gaming/betting sectors.Certifications like CSSLP, OSCP, or Security+; strong problem-solving and team collaboration.Familiarity with GitHub Actions and threat modeling.What We OfferCompetitive salary, hybrid work in Sofia’s tech hub, and growth in global cybersecurity operations.Apply if you thrive at the dev-sec intersection.xqysrnh If you are interested in this challenging position we are looking forward to receiving your comprehensive application for.*** preferably through our ISG career portal or via email.Visit /jobs/search - here you can find new job offers every day.
Requirements
Focus on vulnerability management, code reviews, and compliance in a regulated betting environment.Collaborate with developers to embed security in Agile workflows, minimizing risks across Java, . NET, Python, and PHP stacks.Key ResponsibilitiesConduct SAST, DAST, and penetration testing using tools like Checkmarx, Burp Suite, OWASP ZAP, and Snyk.Review code, manage SCA for third-party libraries, and integrate security into CI/CD pipelines with Jenkins or Azure DevOps.Investigate incidents, support SOC operations, and ensure PCI DSS/ISO compliance while educating developers on OWASP Top 10 risks.Required Qualifications3+ years in software development (Java, .NET, Python, PHP) with transition to application security.Proficiency in SAST/DAST tools (SonarQube, Veracode, Semgrep), WAF configuration, and runtime monitoring (Contrast Security). Knowledge of secure frameworks (Spring, ASP.NET), Unix systems, and regulated industry standards.Preferred SkillsExperience with secrets detection, IaC security, and container scanning in gaming/betting sectors.Certifications like CSSLP, OSCP, or Security+; strong problem-solving and team collaboration.Familiarity with GitHub Actions and threat modeling.What We OfferCompetitive salary, hybrid work in Sofia’s tech hub, and growth in global cybersecurity operations. Apply if you thrive at the dev-sec intersection.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?
Dev Digest 120 - Apple and peers
Dev Digest 121 - AI goes offline