Growe Talents

Application Security Engineer / Penetration tester

Growe Talents · Anywhere
Anywhere Closed
Applications are closed for this role. It was originally posted 2026-08-14. It’s no longer accepting applicants — see roles Growe Talents is still hiring for →, or browse the live openings below.
Type
Full-time
Experience
3+ yr

Our client, Growe, is a leading business advisory and services group in iGaming and Entertainment. Сreators of strategies that work and solutions that scale. Combining strategic vision with hands-on expertise, Growe helps businesses navigate the fast-evolving industry, seize new opportunities, enter new markets, and achieve sustainable growth.

Perfect for those who aim to:

•

Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation;

•

Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production;

•

Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws;

•

Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorization, and business logic.

Experience you’ll need to bring:

•

3 years of experience in Application Security, Product Security, or Penetration Testing;

•

Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner;

•

Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec;

•

Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment;

•

Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures;

•

Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC);

•

Ability to identify complex authorization bypasses, session management flaws, and business logic bugs;

•

Ability to read and analyze modern application code to spot security flaws (will be a plus);

•

Basic understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals (will be a plus);

•

Intermediate level of English (spoken and written).

It's a perfect match if you have those personal features:

•

Strong communication skills to effectively collaborate with engineering, product, and DevOps teams;

•

Result-oriented mindset;

•

Openness to learning.

Our clients offer competitive benefits to support your professional and personal growth, including:

•

Health & Wellness Focus;

•

Global Medical Coverage;

•

Growth Opportunities;

•

Benefits Programs (compensation for the gym/stomatology/psychological service & etc.);

•

Performance-Driven Rewards;

•

Dynamic Work Environment.

Apply, and let your growth journey begin.

GraphQLAWSKubernetes
O
Affiliate Manager
Anywhere Hybrid
Operations
O
CRM Gamification Manager
Anywhere
Operations
O
Customer Research Agent
Anywhere
Operations
See all live roles at Growe Talents →
B
Staff Application Security Engineer
Brex United States
Engineering
$240K–$300K
G
Security Engineer, Application Security
GameChanger Media Remote (US) Remote
Engineering
$120K–$140K
H
Cloud Security Engineer
Hex Technologies New York, NY Remote
Engineering
$198K–$295K
A
Senior Application Security Engineer
Altruist San Francisco, CA Hybrid
Engineering
$200K–$240K
See all Engineering roles →
Applications closed