
Real job — pulled straight from Growe Talents’s careers page · Verified August 28, 2026 · No reposts.
Job description
Growe Talents is hiring a Application Security Engineer / Penetration Tester (Remote) — a full-time, remote role. Apply directly on Growe Talents's careers page below.
Application Security Engineer / Penetration tester
Location: Anywhere
Department: Cybersecurity
Our client, Growe, is a leading business advisory and services group in iGaming and Entertainment. Сreators of strategies that work and solutions that scale. Combining strategic vision with hands-on expertise, Growe helps businesses navigate the fast-evolving industry, seize new opportunities, enter new markets, and achieve sustainable growth.
Perfect for those who aim to:
-
Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation;
-
Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production;
-
Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws;
-
Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorization, and business logic.
Experience you’ll need to bring:
-
3 years of experience in Application Security, Product Security, or Penetration Testing;
-
Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner;
-
Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec;
-
Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment;
-
Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures;
-
Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC);
-
Ability to identify complex authorization bypasses, session management flaws, and business logic bugs;
-
Ability to read and analyze modern application code to spot security flaws (will be a plus);
-
Basic understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals (will be a plus);
-
Intermediate level of English (spoken and written).
It's a perfect match if you have those personal features:
-
Strong communication skills to effectively collaborate with engineering, product, and DevOps teams;
-
Result-oriented mindset;
-
Openness to learning.
Our clients offer competitive benefits to support your professional and personal growth, including:
-
Health & Wellness Focus;
-
Global Medical Coverage;
-
Growth Opportunities;
-
Benefits Programs (compensation for the gym/stomatology/psychological service & etc.);
-
Performance-Driven Rewards;
-
Dynamic Work Environment.
Apply, and let your growth journey begin.
Get Security Engineer jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs




Frequently asked questions
Is Application Security Engineer / Penetration Tester (Remote) at Growe Talents a remote job?
Yes, Application Security Engineer / Penetration Tester (Remote) at Growe Talents is a remote position. This role is open to remote candidates.
How do I apply for Application Security Engineer / Penetration Tester (Remote) at Growe Talents?
You can view the full description and apply for Application Security Engineer / Penetration Tester (Remote) at Growe Talents on EchoJobs: https://echojobs.io/job/growe-talents-application-security-engineer-penetration-tester-mgevn.