Commit
Posted 1mo ago

Application Security Engineer (relocation to Barcelona)

Commit
Bucharest or Barcelona or New York City or Israel or Ukraine
HybridFull Time
Responsibilities
  • planning tests
  • developing tools
  • analyzing vulnerabilities
Requirements
  • Minimum 4 years in research/penetration testing
  • Strong coding skills
  • Experience with web, API
  • Cloud-native
  • Containers
  • Kubernetes
  • Familiarity with SSDLC and CI/CD
  • Experience with Burp Suite
  • Metasploit
  • Fuzzing, and automated testing pipelines
  • LLM/AI penetration testing knowledge
Technical tools mentioned
Burp SuiteMetasploitKubernetesCI/CD pipelinesSecure Software Development Lifecycle (SSDLC)LLM

Job description

Description

We’re running the software that runs the world – and we want you along for the ride. The company is a special place with a unique combination of brilliance, spirit, and great people. Here, if you’re willing to do more, your career can take off. And since software plays a central role in everyone’s lives, you’ll be part of a critical mission.

In this role, you will work with a team of researchers and ethical hackers focused on offensive security testing, automated exploit discovery, and advanced application security research. Your work will directly influence the security posture of the company's products and help scale secure-by-design principles.

This is a hands-on technical role with a strong emphasis on offensive security, code exploitation, automation, and innovation.

Responsibilities:

• Help to reshape JFrog Product Security 

• Plan and execute advanced penetration testing campaigns.

• Develop tools and frameworks for scalable security testing and fuzzing.

• Lead Security innovation by building and managing penetration testing tools \ AI Agents

• Analyze vulnerabilities, perform root cause analysis, and develop proofs of concept.

• Identify systemic product weaknesses and help define long-term mitigations.

• Collaborate with engineering teams to reproduce, triage, and fix vulnerabilities.

• Contribute to security research publications, CVE submissions, and industry knowledge sharing.

• Continuously evolve internal testing capabilities using modern tooling and AI-assisted approaches.

Requirements


• 4+ year experience in Research and penetration testing.

• Strong coding skills and deep technical understanding of web, API, cloud-native, and backend technologies.

• AI and LLM Penetration testing knowldge and Experience 

• Experience with penetration testing tools (Burp Suite, Metasploit, etc.) and Custom Security Tools development.

• Familiarity with modern architectures (e.g., Cloud, microservices, containers, Kubernetes).

• Familiarity with secure software architecture and typical attack vectors.

• Demonstrated ability to do security testing engagements and report technical findings effectively.

• Experience building or integrating automated PT or fuzzing pipelines is a strong advantage.

• Knowledge and hands-on experience with SSDLC tools and CI/CD pipelines

About Commit

End-to-end software, cloud, and cybersecurity consulting and development.

Year founded
2005
Employees
1000
Organization type
Private
Headquarters
IL

Similar jobs

Application Security Engineer roles near Bucharest, Bucharest
1w
Save
Mark Applied
Hide
Senior Application Security Engineer
Bucharest or Cluj-Napoca or Sibiu or Targu Mures or Timisoara
OnsiteFull Time
Infosys
InfosysNYSE: INFY: Provides IT consulting, software development, and business outsourcing services.
10+ YOE10+ years application security experience with SAST/DAST/SCA, penetration and API testing, vulnerability management, secure SDLC advisory, and strong communication skills.
SAST, DAST, SCA, Burp Suite, HCL AppScan, Sonatype Nexus IQ/Lifecycle, Fortify, SonarQube, Black Duck, Azure, Azure DevOps, ServiceNow, Power BI, OWASP Top 10, MITRE ATT&CK