{"id":1411751,"url":"https://alion.io/job/tripleten-application-security-engineer-13","title":"Application Security Engineer","company":{"id":42093,"name":"TripleTen","domain":"tripleten.com","url":"https://alion.io/company/tripleten-comblog","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Comeet","truth_index":{"grade":"A","score":91,"open_postings":51,"ghost_share":0,"stale_share":0.471,"repost_share":0.157,"time_to_fill_p50_days":17,"computed_at":"2026-09-29T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":["GE"],"hiring_countries_total":1,"salary":{"min":4000,"max":6000,"currency":"EUR","period":"month","gross":true,"usd_annual":81912},"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"CI/CD","optional":false},{"name":"GDPR","optional":false},{"name":"IAM","optional":false},{"name":"ISO 27001","optional":false},{"name":"Kubernetes","optional":false},{"name":"LLM","optional":false},{"name":"Machine Learning","optional":false},{"name":"OWASP ASVS","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false},{"name":"SOC 2","optional":false},{"name":"SLSA","optional":true}],"status":"live","first_seen_at":"2026-09-28T17:00:12Z","employer_posted_date":"2026-09-28","last_verified_at":"2026-09-29T17:39:11Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"Description\nNebius Academy (powered by TripleTen) provides assessments and training for tech companies and aspiring professionals worldwide, helping companies & individuals transform their lives through career development and acquiring the new skills needed as a tech professional.\nOur focus on data science, machine learning, and generative AI helps tech-forward companies level up their employees' skills and drive innovation.\nWe are looking for an Application Security Engineer to own product security end to end - from threat modelling and secure design reviews to vulnerability management and security controls embedded into CI/CD.\nYou will work closely with product and platform teams to make security part of the engineering process, building secure defaults and helping prevent vulnerabilities from reaching production without slowing development down.\nWhat you will do\nOwn application and product security end to end, from design reviews and threat modelling to vulnerability remediation and follow-up.\nPartner with product and platform teams to embed security into the development lifecycle rather than treat it as a final review step.\nBuild and improve security controls in CI/CD, including SAST, dependency, secrets, container, and IaC scanning.\nReview application designs and code where security risk is meaningful, and turn recurring findings into secure defaults, shared libraries, lint rules, and CI gates.\nDrive vulnerability management across application code and cloud posture, including triage, risk-based prioritisation, remediation timelines, and external pentest findings.\nStrengthen security in multitenant B2B systems, including tenant isolation, authentication, authorization, RBAC / ABAC, and access controls.\nWork on cloud and Kubernetes security across AWS environments, including IAM, secrets management, network boundaries, and workload hardening.\nHelp translate GDPR, SOC 2, and ISO 27001 requirements into practical engineering controls and system properties.\nDevelop and support a security champions programme to help engineering teams adopt secure practices in their day-to-day work.\nAddress security risks specific to AI and LLM-powered features, including prompt injection, data leakage, and untrusted model output.\nRequirements\n5+ years of engineering experience, including at least 2 years focused on Application Security or Product Security.\nStrong software engineering background with the ability to read, review, and write production code; Python experience is highly preferred.\nDeep practical knowledge of web application security, including OWASP Top 10, ASVS, authentication and session management, OAuth2 / OIDC / SAML, and authorization issues such as IDOR and broken access control.\nExperience securing multitenant or B2B SaaS products, including tenant isolation, RBAC / ABAC, and access control models.\nHands-on experience embedding security into CI/CD, including SAST, SCA, secrets scanning, container scanning, and IaC scanning.\nStrong experience with threat modelling, secure design reviews, and secure code reviews in collaboration with product and engineering teams.\nExperience managing vulnerabilities based on risk, criticality, and exploitability, including remediation prioritisation and escalation when needed.\nWorking knowledge of AWS and Kubernetes security, including IAM, secrets management, network boundaries, and workload hardening.\nStrong communication skills and the ability to explain security risks clearly to engineers, product managers, and auditors.\nFluent Russian and English at B2 level or above.\nNice to have:\nExperience building a DevSecOps practice from scratch.\nExperience running or participating in a Security Champions programme.\nHands-on penetration testing experience.\nExperience securing LLM-powered or AI products.\nExperience with SOC 2 or ISO 27001 from an engineering perspective.\nKnowledge of software supply chain security, including SBOMs, SLSA, image signing, or similar practices.\nWhat we can offer you\nA supportive and proactive work environment.\nCompetitive compensation: 4000-6000 EUR Gross per month\nFully remote and full-time collaboration.\nModern digital tools for seamless collaboration.\nTangible results measured by student success.","description_format":"text","description_chars":4234,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"Russian","level":"Advanced (C1)","optional":false},{"language":"English","level":"Upper-Intermediate (B2)","optional":false}]},"benefits":[],"hiring_locations":[{"name":"Georgia","iso":"GE","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Bootcamps","IT Training & Certification"],"lifecycle":[{"event":"open","at":"2026-09-28T19:21:10Z"}],"liveness":{"score":99,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.993,"p_room":1,"age_days":0,"expected_fill_days":17,"reasons":["conf:4","wave","velocity","win:early","comp:brand"],"computed_at":"2026-09-29T05:45:00Z"},"pay":{"stated_usd_annual":81912,"is_top_pay":false},"html_url":"https://alion.io/job/tripleten-application-security-engineer-13","json_url":"https://alion.io/job/tripleten-application-security-engineer-13.json","meta":{"generated_at":"2026-09-30T01:49:22Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1400,"day_limit":5000,"remaining_today":3600,"minute_limit":60,"resets_at":"2026-10-01T00:00:00Z"}}}