As a Security Engineer for Application Security within the Global Information Security Office (GISO), your mission is to embed seamless, scalable security practices directly into the software development lifecycle at Everpure. In this highly collaborative role, you will partner closely with global development, platform, and security teams to design standardized controls that empower our engineers. By building intelligent automation and tooling integrations, you will ensure our engineering pipelines consistently operate with both uncompromising security and exceptional speed.
• Implement and integrate critical application security controls (such as SAST, DAST, SCA, and secrets scanning) within CI/CD pipelines and Git-based workflows to proactively secure Everpure's software supply chain.
• Develop and maintain scalable automation scripts to streamline complex security checks, significantly improving tooling efficiency and driving consistent security adoption across engineering platforms.
• Exercise independent judgment in analyzing moderately difficult security issues, guiding development teams to effectively identify, troubleshoot, and remediate vulnerabilities in modern application environments.
• Drive the standardization of secure coding best practices and track key AppSec metrics to actively elevate the overall maturity of our global secure development operations.
• A strong foundation in application security concepts (including the OWASP Top 10), web applications, APIs, and modern secure development practices.
• Proficiency in scripting or programming (such as Python) to build automation, coupled with hands-on expertise in navigating CI/CD pipelines and Git-based workflows.
• Demonstrated problem-solving capabilities to tackle moderately complex technical challenges independently, alongside a drive to continuously learn and optimize DevSecOps tooling.
• Exceptional communication and collaboration skills to effectively partner with diverse engineering teams, integrate feedback, and champion secure design principles in a fast-paced environment.
• We are primarily an in-office environment and therefore, you will be expected to work from the Prague office in compliance with Everpure’s policies, unless you are on PTO, or work travel, or other approved leave.
#LI-ONSITE