Application Security Engineer
The role offers a position as Application Security Engineer where the successful candidate will own security for Nebius Academy’s products from design through deployment. Responsibilities include threat modeling, secure design reviews, and embedding security controls into CI/CD pipelines such as SAST, dependency checking, secret scanning, container and IaC scanning. The engineer will collaborate with product and platform teams to shift security left, create secure defaults, shared libraries, lint rules, and CI gates that prevent vulnerabilities from entering production. Additional duties involve managing application and cloud vulnerabilities, enforcing multitenant security measures like RBAC/ABAC, and implementing AWS and Kubernetes hardening for IAM, secrets, and network boundaries. The role also requires translating GDPR, SOC 2, and ISO 27001 requirements into practical engineering controls, and building a security champions program to embed secure practices across engineering teams. Experience with AI and LLM security challenges such as prompt injection and data leakage is also expected.
Source: Himalayas