Evolveum

Application Security Engineer

Evolveum

EMEA

Remote

Intermediate

posted 12 days ago

About Evolveum

Evolveum is the EU-based company behind midPoint, the leading open source complete IGA suite recognized by Gartner and KuppingerCole. MidPoint gives organizations control, visibility, and efficiency to reduce identity risk, simplify compliance, and modernize identity operations. Trusted globally by a community of customers, partners, and other midPoint enthusiasts, it delivers secure IGA with transparency and professional support.

The lively global community of subscribers, contributors, integrators, and other enthusiasts values Evolveum’s attitude on open source and the transparency that comes with it. Moreover, the synergy between Evolveum’s subscriptions and services provided by partners in more than 45 countries enables customers to get the most out of their IGA journey.

Get involved and join the midPoint community today!

The Role

Are you a skilled Application Security Engineer with a hacker’s mindset and a passion for development? Evolveum is seeking a fully remote Application Security Engineer to enhance the security of our leading open-source Identity Governance and Administration (IGA) platform.

The Role

In this role, you will integrate and maintain security testing tools (SAST/DAST, SCA, IaC) within our CI/CD pipelines. You will conduct vulnerability scans, perform internal penetration tests on applications and APIs, and prioritize identified risks. Additionally, you will analyze security reports and vulnerability disclosures from our customers and the open-source community, conduct security-focused code reviews, and collaborate with our Java and Python developers to implement secure fixes. You will also work alongside our Security Architect and CPO on threat modeling and risk assessments, enhance our team's security posture through developer training based on bug bounty findings, and support incident response by analyzing threats and proposing solutions.

Responsibilities

  • Integrate and maintain security testing tools into CI/CD pipelines.
  • Conduct vulnerability scanning and internal penetration tests on applications/APIs.
  • Analyze security reports and vulnerability disclosures from customers and the open-source community.
  • Perform security-focused code reviews and collaborate with developers on secure fixes.
  • Partner with Security Architect and CPO on threat modeling and risk assessments.
  • Deliver developer training based on bug bounty findings and real-world exploits.
  • Support incident response by analyzing threats and preparing public vulnerability disclosures.

Requirements

  • Proven experience in application security, penetration testing, or red teaming.
  • Strong understanding of OWASP Top 10 and common vulnerabilities (SQLi, XSS, CSRF, RCE).
  • Solid software development background, particularly in Java.
  • Good communication skills to explain security issues to technical and non-technical colleagues.

Nice to Have

  • Experience managing Bug Bounty programs (e.g., HackerOne) or vulnerability disclosures.
  • Background in product development or the Identity/Access Management (IAM/IGA) space.

What We Offer

  • Competitive salary starting from 3000 EUR/month, depending on experience.
  • Fully remote work opportunity, preferably within EMEA time zones (CZ/SK).
  • A passionate and dedicated team within a globally recognized EU-based organization, combining the benefits of open-source with financial stability.

Join us in securing the future of open-source identity by clicking the Easy Apply button!

Required skills

Software Development

PYTHON

Product Development

Owasp

Java

CI/CD Pipelines

English level

Professional

Still searching manually?

Let us do the work for you.

Tota works for you

We scan thousands of jobs daily and notify you when there is a match. No searching needed.

Anonymous, safe and free

Your profile stays anonymous. Your employer will not see it. You choose when to become visible.

Ready in 3 minutes

Answer a few questions and create your profile in minutes. No commitment.

About TotaMatch

TotaMatch helps professionals find work that truly fits their work happiness. We believe work is more than just an income. It is a source of fulfillment, growth, and pride. Instead of endlessly scrolling through job boards, TotaMatch works for you. Our platform continuously analyzes thousands of opportunities and identifies roles that align with what truly matters to you. You focus on your work and the people around you. We make sure you never miss a better opportunity.