Growe

Application Security Engineer / Penetration tester

Growe · Anywhere
Anywhere Posted 2026-08-12
Type
Full-time
Experience
2+ yr

Growe welcomes those who are excited to:

Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation;

Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production;

Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws;

Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorization, and business logic.

We need your professional experience:

2-4 years of experience in Application Security, Product Security, or Penetration Testing;

Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner;

Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec;

Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment;

Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures;

Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC);

Ability to identify complex authorization bypasses, session management flaws, and business logic bugs;

Ability to read and analyze modern application code to spot security flaws (will be a plus);

Understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals (will be a plus);

Intermediate level of English (spoken and written).

We appreciate if you have those personal features:

Strong communication skills to effectively collaborate with engineering, product, and DevOps teams;

Result-oriented mindset;

Openness to learning.

We are seeking those who align with our core values:

GROWE TOGETHER: Our team is our main asset. We work together and support each other to achieve our common goals;

DRIVE RESULT OVER PROCESS: We set ambitious, clear, measurable goals in line with our strategy and driving Growe to success;

BE READY FOR CHANGE: We see challenges as opportunities to grow and evolve. We adapt today to win tomorrow.

GraphQLAWSKubernetes
O
AML & Compliance Officer
Europe
Operations
E
Backend .NET Tech Lead
Anywhere
Engineering
M
C&B Specialist
Anywhere
Marketing
See all 30+ roles at Growe →
G
Application Security Engineer / Penetration tester
Growe Talents Anywhere
Engineering
A
Application Security Engineer
Arcadia Power United States Remote
Engineering
$131K–$235K
B
Senior Application Security Engineer
Brex Canada
Engineering
$192K–$240K
C
Application Security Engineer / Architect
Clear Street New York, NY
Engineering
$175K–$210K
See all Engineering roles →

Interested in this role?

Apply directly on the company site — no recruiter middleman, no account required.

Apply now →
Apply on company site