Rivian
Cybersecurity Application Security Engineer
1 мес. назад
SerbiaEuropeSeniorOnsite
graphqlawsreactjavanode.jspythondockerkubernetes
Cybersecurity Application Security Engineer role at Rivian in Belgrade focusing on identifying and remediating security vulnerabilities in applications and supply chain.
Responsibilities
- Review source code and application architectures to identify and communicate security vulnerabilities to development teams.
- Drive the adoption of Software Bill of Materials (SBOM) to provide visibility into the software supply chain and ensure license compliance and vulnerability tracking.
- Implement and manage automated Software Composition Analysis (SCA) to identify and remediate vulnerabilities in open-source and third-party libraries.
- Develop and support automated security tooling and agentic security workflows within CI/CD pipelines to streamline vulnerability triage, third-party scanning, and threat modeling.
- Work closely with the penetration testing team to identify and implement remediations for identified security vulnerabilities.
- Support the implementation of security configurations and countermeasures based on emerging threats and industry trends.
Requirements
- 4+ years of application security experience.
- Proficiency with GraphQL, AWS, React, Java, Node.js, Python, and containerization technologies like Docker and Kubernetes.
- Hands-on experience with reviewing and remediating common SAST and SCA vulnerabilities.
- Strong hands-on coding or scripting skills (e.g., Python, Go) for building security utilities and automation.
- Strong problem-solving and decision-making capabilities.