Application Security Engineer / Penetration tester

Open worldwide
Apply now ↗

Straight to the employer's own application — no middleman.

✓ Screened eligible

Why you can actually get this job

Scope is worldwide and no work-authorisation, presence, language, timezone, or credential restriction was found in the body text.

“Anywhere” Geographic scope — No location restrictions stated — worldwide.

About the role

Growe welcomes those who are excited to

  • Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation;
  • Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production;
  • Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws;
  • Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorization, and business logic.

We need your professional experience

  • 2-4 years of experience in Application Security, Product Security, or Penetration Testing;
  • Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner;
  • Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec;

Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment;

  • Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures;
  • Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC);
  • Ability to identify complex authorization bypasses, session management flaws, and business logic bugs;
  • Ability to read and analyze modern application code to spot security flaws (will be a plus);
  • Understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals (will be a plus);
  • Intermediate level of English (spoken and written).
  • We appreciate if you have those personal features:
  • Strong communication skills to effectively collaborate with engineering, product, and DevOps teams;
  • Result-oriented mindset;
  • Openness to learning.
  • We are seeking those who align with our core values:
  • GROWE TOGETHER: Our team is our main asset. We work together and support each other to achieve our common goals;
  • DRIVE RESULT OVER PROCESS: We set ambitious, clear, measurable goals in line with our strategy and driving Growe to success;
  • BE READY FOR CHANGE: We see challenges as opportunities to grow and evolve. We adapt today to win tomorrow.
Apply now ↗

Straight to the employer's own application — no middleman.

At a glance

  • EmploymentNot stated in posting
  • Hiring scopeanywhere
  • SalaryNot disclosed
  • Posted12d ago

Keep this one

Sign in to save jobs and track what you've applied to.

Sign in

Did you get this job?

Tell us and we'll mark Growe as a company that has actually hired in the Caribbean. It's the most useful thing on this board and it only exists because people report it.

I got hired here →

Something wrong with this listing?

← All eligible jobs