Application Security Engineer | Senior

NordVPN logo
Full Time
remote
Cybersecurity
Bucharest
The world’s most advanced VPN, and a whole lot more. 

If you’re a curious problem-solver who carves their own path, join the team behind Threat Protection Pro, the NordLynx protocol, and the fastest VPN on the planet—tools that put privacy, security, and control back in people’s hands.

Your impact? Helping millions take back control of their online security, privacy, and data.

Main Responsibilities

  • Ensure software design security and define secure implementation practices by syncing with teams responsible for the actual product development. 
  • Ensure that security-related communication between technical teams involved in releasing the product is smooth (act as a “glue” between all teams so everyone’s on the same page);
  • Develop scripts, security automation tools (e.g. for JIRA and GitLab) to enhance application security testing processes;
  • Create tasks for the product's security reviews (SAST/DAST/SCA results, application security testing, etc.).
  • Cooperate with product teams to learn about changes introduced into the product early to make educated security decisions.
  • Ensure mobile/desktop applications and browser extensions are sufficiently tested.
  • Support internal and external audits;
  • Design and deliver training for security engineering awareness & adoption.
  • Actively look for internal security gaps within the product or organization overall.
  • Address security questions and give advice regarding the direction of the product's security.

Core Requirements

  • Proven experience in mobile/desktop applications security assessment: planning, testing, methodologies, and vulnerability reporting;
  • Good understanding of how networks work (OSI and TCP/IP models) with a particular focus on VPNs;
  • Experience working with stakeholders to define the scope of security tests and identify remediation actions to address any vulnerabilities identified;
  • Knowledge of secure coding practices (particularly differences between different low-level languages, such as C, C++, and Rust, and their respective security considerations);
  • Sense of ownership with strong problem-solving and investigation skills;
  • Experience with different OS (Linux, Android, iOS, macOS, Windows) security topics;
  • Ability to build and maintain relationships, influence key stakeholders across the business;
  • Ability to make product-related business decisions based on threats and vulnerabilities affecting it;
  • A healthy dose of assertiveness combined with an ability to compromise.

Apply for this job

Cybersecurity

Bucharest

NordVPN logo
 
 
 
 
 
 

Nord Security is committed to building an inclusive workplace with a diversity of backgrounds. We welcome applications from people of all ages, gender identities, sexual orientations, racial identities, ethnicities, religious beliefs, and disability statuses. To reduce the chance of unconscious bias, you may submit your CV without a photograph or other redundant information like age or marital status.

By submitting your application, you acknowledge that it may be processed using automated tools for evaluation purposes. .

By filling in this form you confirm that you have read and understood the Privacy Notice for Recruitment Candidates.

Our values

Our values are rooted in the actions of our people. They describe how we solve problems, make decisions, and ultimately - reach our goals as a team.

amazing picture about the company values

Future shapers

Always hungry for the new big thing. Pushing the boundaries and finding innovative solutions.

amazing picture about the company values

Restless achievers

There’s no impossible - an obstacle is often an opportunity. We sometimes fail, but we learn quickly and find a way to reach our goals.

amazing picture about the company values

Self-movers

We care about what happens in our company and take care of things without being asked.