Logo for CCBill

Application Security Engineer

Role overview

Qualifications

  • Minimum 3 years of experience in application security, penetration testing, software development or a related information security role.
  • Experience performing web application security assessments and penetration testing.
  • Understanding of secure software development practices.
  • Strong knowledge of OWASP Top 10, CWE, NIST security guidance, and secure coding principles.

Responsibilities

  • Perform manual and automated security assessments of web applications and APIs.
  • Conduct application penetration testing to identify vulnerabilities, security weaknesses, and configuration issues.
  • Participate in threat modelling exercises and security design reviews.
  • Support the implementation and operation of security testing within CI/CD pipelines.

Key facts

  • Remote from: Serbia
  • Full time
  • Mid-level (2-5 years)
  • Application Security Engineer
  • English

Hard skills

Other skills

  • Analytical Skills
  • Problem Solving
  • Communication
  • Collaboration
  • Willingness To Learn

About the company

CCBill logo

CCBill

Digital Payments & Money Transfer

CCBill is a leading global payment processor and ecommerce provider. As one of the largest third-party payment processors, CCBill is much more than a payment processor. CCBill is an ecommerce platform that can provide expert support and empowerment to your expanding relationships. Whether it's through consistent on-time payouts, distinctive affiliate tools, or the comprehensive and proprietary set of account management options, CCBill understands online business like few others, and has been offering industry-leading solutions since 1998. Processing for more than a billion dollars in transactions each year, CCBill has the reliable problem-solving techniques, phenomenal consumer support, and innovative solutions to support all markets.

Company details

IndustryDigital Payments & Money Transfer
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

CCBill is an online payment services provider used by more than 30,000 websites globally that supports the needs of both new and established businesses in the e-commerce and online space.

We are seeking an Application Security Engineer to support the secure development of internally developed applications. The successful candidate will perform application security testing, code reviews, threat modelling and vulnerability assessments while supporting the integration of security controls into the software development lifecycle.

The role will work closely with the development, architecture and Information Security team to identify and remediate security risks and improve the overall security posture of applications.

Location: Serbia

Working Hours: Monday to Friday (40 hours); 1PM-9PM CET, fully remote

Key Job Requirements:

Application Security Testing:

  • Perform manual and automated security assessments of web applications and APIs.
  • Conduct application penetration testing to identify vulnerabilities, security weaknesses and configuration issues.
  • Document findings, remediation recommendations and risk ratings in clear technical reports.
  • Validate remediation activities through re-testing

Secure Development:

  • Participate in threat modelling exercises and security design reviews.
  • Perform security-focused source code reviews of internally developed applications.
  • Support developers in understanding and remediating identified vulnerabilities.
  • Promote secure coding practices and security awareness across development teams.

DevSecOps and Security Automation

  • Support the implementation and operation of security testing within CI/CD pipelines.
  • Assist with the deployment and tuning of:
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Software Composition Analysis (SCA)
    • Secrets detection controls
    • Contribute to security automation initiatives using Jenkins, GitLab and Bitbucket.

Vulnerability Management

  • Track and manage vulnerabilities identified during security testing activities.
  • Work with development teams to prioritise and remediate findings.
  • Assist in assessing application security risks and recommending appropriate mitigation measures.

Collaboration

    • Work closely with development, architecture, infrastructure, and Information Security teams to improve application security.
    • Support security reviews prior to production deployments.
    • Contribute to the continuous improvement of application security standards, processes and procedures

Key Skills & Qualifications:

Required

  • Minimum 3 years of experience in application security, penetration testing, software development or a related information security role.
  • Experience performing web application security assessments and penetration testing.
  • Understanding of secure software development practices.
  • Experience reviewing source code and identifying common security vulnerabilities.
  • Strong knowledge of:
    • OWASP Top 10
    • CWE
    • NIST security guidance
    • Secure coding principles

Technical Skills

  • Knowledge of web technologies, APIs, databases and networking concepts.
  • Familiarity with programming languages such as:
    • Java
    • .NET/C#
    • Python
    • JavaScript
    • Perl
  • Understanding authentication, authorisation and session management concepts.

Tools

  • Experience with some of the following:
    • Burp Suite
    • OWASP ZAP
    • Nessus
    • Metasploit
    • Wireshark
    • SAST and DAST tools

CI/CD and DevSecOps

  • Exposure to:
    • Jenkins
    • GitLab
    • Bitbucket
    • Agile development environments

Personal Attributes

  • Strong analytical and problem-solving skills.
    • Effective verbal and written communication skills.
    • Ability to work collaboratively within cross-functional teams.
    • Willingness to learn and develop expertise in application security and DevSecOps practices.
  • Proactive, strategic thinker who can turn concepts into actionable plans.
  • Advocates security improvement initiatives while understanding business priorities and constraints.
  • Demonstrated experience in mentoring, coaching, and supporting the growth of a diverse and distributed team.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Application Security Engineer Related jobs

Other jobs at CCBill

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.