应用安全工程师
Application Security Engineer
关于Nebius:
Nebius正在引领全球AI经济的云基础设施新时代。我们正在构建一个全栈AI云平台,支持开发者和企业从数据和模型训练到生产部署,而无需承担构建大型内部AI/ML基础设施的成本和复杂性。
由工程师打造,面向工程师。从大规模GPU编排到推理优化,我们在计算、存储、网络和应用AI领域都负责解决难题。
在纳斯达克上市(NBIS),总部位于阿姆斯特丹,我们拥有遍布欧洲、英国、北美和以色列的全球研发中心。我们的团队超过1500人,包括数百名在硬件、软件和AI研发方面有深厚专业知识的工程师。
应用安全
该团队负责Nebius主要公开产品的安全性:Compute、VPC、Managed K8s、Marketplace、Managed Soperator等。这包括构建安全的SDLC、威胁建模和漏洞管理平台。
职位描述
我们正在寻找一位高级/资深应用安全工程师,通过识别和缓解漏洞、实施最佳安全实践以及与开发团队合作,确保我们软件的安全性。理想的候选人应具备安全编码、威胁建模和构建安全SDLC的扎实背景。
您将负责
- 在公司规模上构建和维护应用安全态势管理(ASPM)。
- 作为CI/CD流水线的一部分,自动化并支持SAST、SCA等工具。
- 改进SAST、秘密检测规则,保持误报率低。
- 识别、分析和修复应用安全漏洞。
- 与开发团队合作,将安全最佳实践整合到软件开发生命周期(SDLC)中。
- 开发和维护开发团队的安全编码指南。
- 为新旧应用程序进行威胁建模和风险评估。
- 为开发团队提供有助于安全相关工作的工具,如威胁建模、漏洞检测等。
- 跟踪最新的安全威胁、漏洞和缓解技术。
- 作为其他团队的应用安全专家提供支持。
我们期望的条件
- 6年以上应用安全经验。
- 熟悉常见的应用安全风险(例如OWASP Top 10)及其缓解方法。
- 具有安全工具和流程的经验
查看英文原文
About Nebius:
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
Application Security
The team is responsible for the security of Nebius's main public offerings : Compute, VPC, Managed K8s, Marketplace, Managed Soperator, and others. This includes building out the Secure SDLC, threat modeling, and vulnerability management platforms.
The Role
We are looking for an Senior/Staff Application Security Engineer who will ensure the security of our software by identifying and mitigating vulnerabilities, implementing best security practices, and collaborating with development teams. The ideal candidate will have a strong background in secure coding, threat modeling and building Secure SDLC.
What you will do
- Build and maintain Application Security Posture Management (ASPM) at the Company scale.
- Automate and support SAST, SCA tools, etc as part of CI/CD pipelines.
- Improving SAST, secrets detection rules. Keeping false positive rate low.
- Identify, analyze, and remediate application security vulnerabilities.
- Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC).
- Develop and maintain secure coding guidelines for development teams.
- Conduct, run threat modeling and risk assessments for new and existing applications.
- Provide development teams with instruments that facilitate security-related work like threat modelling, vulnerability detection, etc.
- Stay updated on the latest security threats, vulnerabilities, and mitigation techniques.
- Serve as an application security subject matter expert to other teams.
What we look for
- 6+ years of experience in application security.
- Strong knowledge of common application security risks (e.g. OWASP Top 10) and how to mitigate them.
- Experience with secure coding practices in languages such as Python, Go, Java, or JavaScript.
- Proficiency in a common programming language (such as Go or Python) with a willingness to learn Go, if necessary.
- Hands-on experience with security testing tools (Burp Suite, ZAP, Semgrep, etc.).
- Understanding of authentication protocols like SAML or OIDC.
- Experience in conducting threat-modeling sessions.
Bonus points
- Confidence in presenting your ideas and opinions in a manner that can be challenged, while responding well to feedback.
- Experience in designing, building, and maintaining security automation.
- Experience in translating compliance and regulation requirements into technical specifications.
- Experience in exploiting vulnerabilities in web applications, Linux kernels, containers, and networks.
- Security certifications such as OSCP or OSWE.
We conduct coding interviews as part of the process.
Benefits & Perks:
- Competitive compensation
- Career growth and learning opportunities
- Flexibility and ownership
- Collaborative and innovative culture
- Opportunity to work on impactful AI projects
- International environment and talented teams
What's it like to work at Nebius:
Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI
Equal Opportunity Statement:
Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.
Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.
If you need accommodations during the application process, please let us know.
Originally posted on Himalayas