This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Working on the Security Functional Team, you'll play a pivotal role in ensuring our security capabilities keep pace with our rapid product development, directly protecting our users across all our products. You'll also maintain incident detection and response capabilities for the company, and work on general security related projects.
Deliver on Internal red-team operations (simulated attack scenarios)
Support security triage
Requirements:
7+ years of experience in web or application security (performing security assessments, vulnerability research, penetration testing, or secure code review)
Advanced programming or scripting experience with JavaScript
Experience with at least one WebView technology (WebKit, WebView2, Chromium WebView, etc.) and understanding of browser security models (SOP, CSP, CORS, SameSite cookies)
Hands-on experience identifying and exploiting web vulnerabilities (XSS, CSRF, injection attacks, authorization flaws, etc.)
Familiarity with security testing tools and frameworks
Experience partnering and collaborating with Product Engineers, advising on security matters and helping teams ship secure code faster
Experience shaping how an organisation thinks about security - driving best practices, improving processes, and raising the bar across teams
Nice to have:
Any additional experience with our stack is a bonus: Swift/Kotlin/C#/JavaScript (native apps) or JavaScript/Perl/Go (search)