Application Security Specialist

The Zone
United States
28 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Server Applications Software Applications C++ (Programming Language) Cloud Computing Security Static Program Analysis Software Debugging Dynamic Program Analysis Python (Programming Language) Reverse Engineering Software Security Information Technology Vulnerability Analysis

Job description

  • Reproduce and triage incoming vulnerabilities from security automation/bug bounty programs, then propose granular fixes to engineers
  • Discover vulnerabilities and construct exploits for core Parallels applications such as Parallels
  • Remote Application Server
  • Assist in the CVE disclosure process
  • Provide threat models and design reviews for teams throughout the company
  • Assist in tuning existing static analysis, dynamic analysis, and dependency management tools

Requirements

  • BSc / MS in computer science or a related field
  • Previous CVEs in desktop applications
  • Proficiency with reverse engineering tools
  • Significant experience in memory exploitation techniques (e.g. gaining code execution from
  • memory vulnerabilities in modern operating systems)
  • Familiarity with cloud security best practices
  • 3+ years of industry experience
  • OSCP / OSWE / OSED / RET2 certification

Will definitely be a plus:

  • An attacker mindset: engineers will often want proof before fixes are implemented
  • Eagerness to learn - you are not expected to know everything coming in, but you should continuously learn new techniques on the job
  • The ability to communicate clearly, acknowledge mistakes, and disagree when necessary
  • Demonstrable passion for offensive security
  • Experience reading, writing and debugging C++ and Python code
  • Basic experience with memory exploitation techniques
  • Demonstrable experience with web exploitation techniques and tools (e.g. PortSwigger lab scoreboards)
  • Excellent written and oral communication skills, We are looking for a highly motivated and talented Application Security Engineer to join their team.

In this role, you will help make security decisions that impact millions of users while gaining hands-on experience in exploit development, vulnerability research, and CVE discovery. The ideal candidate combines an attacker mindset with strong attention to detail and enjoys collaborating with engineering teams to build secure, scalable solutions.

Benefits & conditions

Our client is a global technology company whose products are used by millions of customers worldwide. They are investing heavily in security, innovation, and engineering excellence, offering an opportunity to work on meaningful challenges with real-world impact.

You’ll be joining the company at an exciting stage of growth, working alongside experienced professionals in a collaborative environment where new ideas are encouraged and technical expertise is valued.

The company also promotes a flexible, people-first culture, empowering employees to work in the way that suits them best while maintaining a healthy work-life balance.

About the company

ZONE3000 is a 2400+ people family that forms a new cultural code in the software development business. For 25 years we have been focusing on the highest quality of projects and empowering people to think big and make a difference. We are looking for talents who want to create and improve technological solutions for tomorrow and make things as best possible.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · World Congress 2025

2:08 min

The vending machine trap in software debugging

Jen Callou Jen Callou · Europe 2026 Virtual

4:25 min

Evolution of deployment models from application servers

Adam Bien · World Congress 2021

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

3:55 min

Establishing blameless dialogue surrounding critical software security vulnerabilities

Chris Heilmann +2 · LIVE

Videos

See all

Related articles

See all