Verified current Job

AppSec - Vulnerability Management Engineer

ABOUT THE TEAM

Job Full source details
Trendyol Istanbul, Istanbul / Maslak Source published Jun 20, 2023 Verified 1 hour ago
✓ 100% verification score · Source: Trendyol (lever) · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
EmploymentFull-time

Overview

ABOUT THE TEAM

Full job description

ABOUT THE TEAM

We’re shaping the future of financial technology at Trendyol. As Trendyol’s technology teams, we’re not only building for today we’re designing the financial experiences of tomorrow. From payment infrastructure and digital wallets to smart credit systems and personalized financial services, we create solutions that empower millions of users across our ecosystem. With Trendyol Pay, we enable fast, secure, and seamless payment journeys. Through Trendyol Finance, we develop inclusive and accessible products that simplify financial decisions.

We are united by a shared purpose:To create a positive impact in our ecosystem by enabling commerce through technology

About the Role As an Application Security Engineer, you’ll work closely with Trendyol’s engineering teams to enhance application security across our platforms. You’ll perform web and mobile security testing, validate fixes through code reviews, and provide expert guidance on secure coding practices. In this role, you’ll support our bug bounty program, develop custom security tools, and help drive root-cause analysis and remediation. We’re looking for a collaborative, open-minded teammate who is eager to improve, communicate clearly, and promote security best practices throughout the organization.

Ability to work collaboratively in a team environment and is a friendly, humble, responsible teammate. Be a subject matter expert and guidance to Trendyol Engineering for secure coding practices, application security. Experience in performing web security testing on web applications and mobile applications. Ensuring to confirm of the fix of the vulnerability by making manual code review on the relevant commit. Experience identifying and protecting against web application and web-service security vulnerabilities including those found in the OWASP Top 10. Experience in fixing vulnerabilities, documenting and remediation guidance for discovered vulnerabilities. Developing custom security tools and security rules(e.g. Semgrep / Nuclei) Promoting security best practices among developers. Ability to conduct root cause analysis against vulnerabilities and determine feasible technical solutions. Managing Bug Bounty Platform.

Experience with multiple programming/scripting languages (such as, Java, Golang, Python etc.) Having excellent communication skills. Experience with vulnerability management and enterprise remediation efforts. Being an Agile minded team player. Eagerness on self-improvement, open-minded, future-oriented. English language skills for reading technical documentation and to fix the vulnerabilities with international developers. Professional certification (e.g. eWPT , eWPTXv2 , OSWE , eMAPT , GWAPT ) preferred. Familiarity with front-end and back-end web application frameworks (i.e. Spring, Gin, React, etc). Bonus points for community contributions like public CVEs, bug bounty recognition, blogs, etc.

Tips for this job

Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

laptop-ats-crawler v3

Original authoritative source

Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Trendyol (lever) ↗

Browse current Job and Scholarship listings from Trendyol (lever) →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books