VacanciesCompanies
PackagesBlog
logoShtat.az

Azərbaycanda iş axtarışı və karyera inkişafı üçün etibarlı platforma

© 2026 Shtat.az

Information Security - Cybersecurity

Application Security Engineer

🏢Kapital Bank📍Address not specifiedFull-time📅12.05.2026💰Interview-based

Job Description & Requirements

2-4 years of experience in Application Security, Product Security, or a development role with a strong security focus. Strong knowledge of OWASP Top 10 (Web), OWASP API Security Top 10, and secure development practices. Hands-on experience with SAST, DAST, and SCA tools such as Checkmarx, SonarQube, Veracode, Semgrep, or Snyk; ability to triage and prioritize findings from automated security scanners. Experience integrating security tooling into CI/CD pipelines (GitHub Actions, GitLab CI, or Jenkins) and familiarity with shift-left security principles. Working knowledge of cloud environments (AWS, Azure, or GCP) including IAM, secrets management, and network security controls. Proficiency in Python, Bash, or PowerShell for automating security checks and workflows. Ability to write or review code from a security perspective across common languages such as Java, Python, or JavaScript. Experience conducting secure code reviews and participating in design review sessions. Basic understanding of container and Kubernetes security concepts. Familiarity with vulnerability scoring (CVSS) and vulnerability management processes. Understanding of MITRE ATT&CK framework and the Cyber Kill Chain. Certifications preferred: OSWE, CWEE, CDP, CDE, or equivalent.

Job Responsibilities

The Mid-Level Application Security Engineer will work alongside development and DevOps teams to integrate security into the software development lifecycle (SDLC). This role focuses on SAST/DAST/SCA tooling, secure code review, CI/CD pipeline security, and promoting security by-design across engineering teams.

Apply Now

This position requires application on the employer's website.