Constructor Knowledge

Application Security Engineer (Remote in Bulgaria, Germany, Italy, Serbia, Turkey)

Constructor Knowledge  •  Istanbul, TR (Remote)  •  1 month ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

We are seeking an Application Security Engineer with a strong background in web application security design, secure development practices, and vulnerability testing. This role also requires practical experience with Software Bill of Materials (SBOM) management and implementation, contributing to our secure SDLC and software supply chain risk reduction efforts.

Duties and Responsibilities:

  • Perform threat modeling, security architecture review, and design analysis for web applications and APIs.
  • Conduct manual and automated security testing during development and pre-release stages.
  • Design and implement security pipelines (including SAST and DAST) and integrate them into the SDLC process.
  • Implement and manage SBOM generation and consumption processes across the SDLC.
  • Collaborate with development teams to ensure timely remediation of identified vulnerabilities.
  • Maintain security guidance aligned with OWASP best practices and provide trainings for development teams.
  • Stay current with evolving application security threats, tools, and industry developments.

Qualifications and Experience:

  • 3–5 years of experience in application security, with a focus on web applications and API security.
  • Good knowledge of at least one scripting or programming language (e.g., Python, JavaScript, C#, or Go).
  • Experience with tools like OWASP ZAP, Burp Suite, Snyk, or similar.
  • Familiarity with secure coding, DevSecOps, and container security concepts.
  • Strong understanding of CVE, CVSS, and vulnerability disclosure workflows.
  • Excellent command of business English.
  • Preferred Qualifications:
  • Knowledge of SBOM standards (CycloneDX, SPDX) and experience integrating SBOM tooling into CI/CD pipelines.
  • Knowledge of software composition analysis (SCA) tools.
Constructor Knowledge

About Constructor Knowledge

Constructor Knowledge serves as the educational and research backbone of Constructor Group and unites a powerful ecosystem of institutions to deliver research-driven education and support transformation across K–12, higher education, professional learning, executive learning, and research. Our flagship research and educational center is Constructor University, a non-profit, research-oriented, #1 private university in Bremen, Germany. Other entities within the ecosystem include Constructor Academy (Germany & Switzerland), Nexford University (USA), Constructor Talent School, Constructor Start, Constructor Alumni and Constructor Campus.

We deliver both traditional and online learning services and advisory support for learners of all ages. Under the leadership of Oznur Bell (CEO), we oversee educational tools, programs, and outreach functions, including student recruitment, marketing, and communications.

Our mission is to empower learners worldwide by cultivating deep knowledge, critical thinking, and practical skills; to foster educational innovation; and to integrate digital learning tools. We strive to support science, research, and technological progress, and equip individuals to address today’s global challenges.

Constructor Group is a global institution built on the principle that knowledge solves all evil, enhancing the impact of scientists, teachers, and students through its integrated ecosystem of science, technology, and education. The group has three main pillars—Constructor Knowledge, Constructor Capital, and Constructor Tech—and focuses on fundamental technologies like generative AI, computing, robotics, and neuroscience to advance science and education.

Industry
Education & Training
Company Size
11-50 employees
Headquarters
Schaffhausen, CH
Year Founded
Unknown
Social Media