Growe logo

Application Security Engineer / Penetration Tester (Remote)

Growe

Remote
Full-time
Mid Level
Senior
2+ yrs
Salary not listedPosted 4d ago

Real job — pulled straight from Growe’s careers page · Verified August 28, 2026 · No reposts.

Job description

Growe is hiring a Application Security Engineer / Penetration Tester (Remote) — a full-time, remote role. Apply directly on Growe's careers page below.

Application Security Engineer / Penetration tester

Location: Anywhere

Department: Cybersecurity

Growe welcomes those who are excited to:
  • Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation;

  • Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production;

  • Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws; 

  • Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorization, and business logic.

We need your professional experience:
  • 2-4 years of experience in Application Security, Product Security, or Penetration Testing; 

  • Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner;

  • Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec; 

  • Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment;

  • Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures; 

  • Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC);

  • Ability to identify complex authorization bypasses, session management flaws, and business logic bugs;

  • Ability to read and analyze modern application code to spot security flaws (will be a plus); 

  • Understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals (will be a plus);

  • Intermediate level of English (spoken and written).

We appreciate if you have those personal features:
  • Strong communication skills to effectively collaborate with engineering, product, and DevOps teams;

  • Result-oriented mindset;

  • Openness to learning.

We are seeking those who align with our core values:
  • GROWE TOGETHER: Our team is our main asset. We work together and support each other to achieve our common goals;

  • DRIVE RESULT OVER PROCESS: We set ambitious, clear, measurable goals in line with our strategy and driving Growe to success;

  • BE READY FOR CHANGE: We see challenges as opportunities to grow and evolve. We adapt today to win tomorrow.

Get Application Security Engineer / Penetration Tester (Remote) jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Homebot logo

Senior Backend Engineer

$145k–$175kDenver, CO
✓ From careers page· 54m ago
K2 Space logo

Vehicle Operations Engineering Intern

$62k–$83kTorrance, CA
✓ From careers page· 1h ago
Brillio logo

Software Development Lead

Bangalore, Karnataka
✓ From careers page· 2h ago
Alongside logo

Senior Test Automation Engineer

Porto, Porto District, Portugal
✓ From careers page· 5h ago

Frequently asked questions

Is Application Security Engineer / Penetration Tester (Remote) at Growe a remote job?

Yes, Application Security Engineer / Penetration Tester (Remote) at Growe is a remote position. This role is open to remote candidates.

What skills are required for Application Security Engineer / Penetration Tester (Remote) at Growe?

The required skills for Application Security Engineer / Penetration Tester (Remote) at Growe include: GraphQL, SAML, AWS, Kubernetes, Communication.

What is the seniority level for Application Security Engineer / Penetration Tester (Remote) at Growe?

Application Security Engineer / Penetration Tester (Remote) at Growe is a Mid Level / Senior level position.

How do I apply for Application Security Engineer / Penetration Tester (Remote) at Growe?

You can view the full description and apply for Application Security Engineer / Penetration Tester (Remote) at Growe on EchoJobs: https://echojobs.io/job/growe-application-security-engineer-penetration-tester-k6lro.