Senior Application Security Engineer
Remote in Armenia, & 4 others
Security.Engineering& 4 others
Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobChoose an option
We are looking for a Senior Application Security Engineer to join our forward-thinking team.
We are delivering a Unified Automation Platform (Internal Developer Platform) to standardize delivery, reduce security gaps, and enable secure self-service across Azure and on-premises VMware. You will lead critical security-tooling integrations and policy automation for a governance-heavy environment.
Responsibilities
- Implement and operate the certificate-management integration with Venafi: issuance workflows and distribution across F5, Azure Key Vault, and VM/OS certificate stores, including renewal/rotation automation
- Build and maintain the secrets-management integration (OpenBao, Azure Key Vault): configuration-as-code for authentication methods, namespaces, mounts, policies, and dynamic secrets engines (database, cloud)
- Implement the Privileged Access Management (PAM) "break-the-glass" workflow: time-boxed grant requests, approval-chain automation, session recording hooks, and audit-trail logging
- Build SIEM and WAF alert-integration pipelines (alert feed ingestion, entity correlation, severity views) and the Vulnerability Dashboard, integrating findings from SAST/DAST/SCA/IAST/ASPM scanners
- Implement Policy as Code checks (OPA/Conftest, Azure Policy): baseline policy library, CI gate integration, and exemption/waiver workflow automation
- Support the platform's Auth/RBAC configuration from a security-tooling perspective (Entra ID, Active Directory, GPOs, M365 groups), ensuring audit-retention settings are correctly applied
- Work with the Network Architect to translate firewall/WAF policy requirements (PaloAlto, F5, Cloudflare) into the SIEM/WAF alert integration and Vulnerability Dashboard
- Support SOC and IAM teams during security reviews, preparing evidence and configuration details for security-sensitive integrations
- Troubleshoot and remediate security-tooling issues during Implementation and Adoption
Requirements
- 3+ years of hands-on experience implementing security-tool integrations: certificate-lifecycle management (Venafi or equivalent), secrets management (OpenBao, Key Vault), and PAM workflows
- Practical experience with SIEM/SOAR alert pipelines and vulnerability-management tooling (SAST/DAST/SCA/IAST/ASPM)
- Experience implementing Policy as Code checks (OPA/Conftest, Azure Policy) and CI/CD gate enforcement
- Working knowledge of enterprise identity and access management (Entra ID, Active Directory, RBAC/claims-based authorization)
- Familiarity with firewall/WAF concepts (PaloAlto, F5, Cloudflare) sufficient to define alerting/finding-correlation requirements
- Ability to work within governance-heavy, security-sensitive change-control processes
- Excellent command of written and spoken English (B2+ level)
Nice to have
- Experience integrating security tooling with a Backstage-based (or comparable) developer portal
- Familiarity with supply-chain security practices (artifact signing/SBOM, e.g., cosign/Sigstore)
- Knowledge of Conditional Access automation (Entra ID/Microsoft Graph API)
- Experience with Infrastructure as Code (Terraform/OpenTofu) for implementing security modules
