Описание вакансии
Cybersecurity Application Security Engineer
Rivian, Belgrade
Rivian is on a mission to keep the world adventurous forever. This goes for the emissions-free Electric Adventure Vehicles we build, and the curious, courageous souls we seek to attract.
Vulnerability Management: Review source code and application architectures to identify and communicate security vulnerabilities to development teams.
Supply Chain Security: Drive the adoption of Software Bill of Materials (SBOM) to provide visibility into the software supply chain and ensure license compliance and vulnerability tracking.
3rd Party Risk Mitigation: Implement and manage automated Software Composition Analysis (SCA) to identify and remediate vulnerabilities in open-source and third-party libraries.
CI/CD Pipeline Security: Develop and support automated security tooling and agentic security workflows within CI/CD pipelines to streamline vulnerability triage, third-party scanning, and threat modeling.
Remediation Support: Work closely with the penetration testing team to identify and implement remediations for identified security vulnerabilities.
Threat Response: Support the implementation of security configurations and countermeasures based on emerging threats and industry trends.
Experience: 4+ years of application security experience.
Technical Proficiency: Proficiency with GraphQL, AWS, React, Java, Node.js, Python, and containerization technologies like Docker and Kubernetes.
Vulnerability Expertise: Hands-on experience with reviewing and remediating common SAST and SCA vulnerabilities.
Automation: Strong hands-on coding or scripting skills (e.g., Python, Go) for building security utilities and automation.
Soft Skills: Strong problem-solving and decision-making capabilities.
#engineer #serbia