Teknologji Informacioni (IT)Prishtinë1 javë më parëFull Time
Application Security Engineer
The Company
ISA Consulting delivers end-to-end Digital Transformation, Digital Consulting, and Business Process Services solutions across all Tech Stacks. The company serves clients from numerous industries and business verticals. Its teams include Full Stack Developers, Data Engineers, Architects, Project Managers, Quality Analysts, and Strategists working across several time zones.
Job Summary
ISA Consulting seeks an Application Security Engineer to support the security of its eDiscovery and AI platform throughout the software development lifecycle. This position centers on manual secure-code reviews, application-security testing, and collaboration with engineering teams to identify and remediate vulnerabilities before production release. The work is practical and technically diverse, involving code reviews across different products, languages, and frameworks; full ownership of reviews; and development of supporting tools and automation. The successful candidate will communicate technical matters effectively, work autonomously, prepare clear evidence-supported findings, and collaborate with engineering through remediation.
Responsibilities & Duties
Code Review & Assessment
Conduct detailed manual, tool-supported, and AI-supported code reviews to detect vulnerabilities prior to release.
Take responsibility for assigned reviews from initial scoping and repository discovery through documented findings and remediation follow-up.
Address blockers independently or escalate them when needed, while engaging engineering teams without daily supervision.
Prepare comprehensive, evidence-based review reports containing severity classifications, reproduction information, and remediation recommendations; track these in Jira until closure against established SLAs.
Work with engineering teams to assess and resolve findings produced by code reviews, SAST/DAST, and other assessment tools.
Security Engineering & SDLC
Support security assessments for new products, features, and services.
Advise on secure design, architectural, and implementation choices.
Use secure development lifecycle methods, including threat modeling and security testing.
Manage dependency and supply-chain risks, including SCA, SBOM, and vulnerability triage, and help expand security controls within CI/CD pipelines.
Collaborate with Security Operations and Infrastructure teams on security tools and automation.
Influence & Enablement
Develop understandable security guidance and documentation for engineering teams.
Support security training initiatives and the Security Champions program.
Requirements & Skills
Act as a professional example and encourage professional conduct.
Demonstrate outstanding written and spoken communication abilities when working with people across disciplines and organizational levels.
Be prepared to contribute to several projects, assignments, and IT competency areas.
Maintain an open-minded, solution-focused approach.
Show strong diagnostic and problem-solving abilities.
Be committed to providing an exceptional customer-service experience for all employees.
Education & Experience
Hold a Bachelor's degree in a relevant discipline such as Computer Science, Software Engineering, Security, or similar, or possess an equivalent mix of education, training, and experience.
Have at least 3-5 years of professional experience in application security or software engineering, including a minimum of 2 years focused on secure code review, application security testing, or secure development.
Possess practical software-development experience adequate for reading and reasoning about production code.
Have professional experience carrying out security assessments, including manual secure-code reviews.
Have professional experience creating or evaluating threat models.
Be experienced with SAST, DAST, and SCA tools, such as Semgrep, CodeQL, Burp Suite, and Dependency-Track.
Be able to read and assess unfamiliar codebases in several languages, including C#/.NET, Node/TypeScript, Java, Python, and Ruby.
Understand the HTTP protocol, web frameworks, and web and cloud architectures.
Understand cryptography in application code, including key handling, secrets management, and encryption in transit and at rest.
Be familiar with multi-tenant SaaS security, especially tenant isolation and access control.
Have used AI-assisted tools such as Claude Code and Copilot for code-review or triage workflows.
Know LLM/GenAI application-security topics, including prompt injection, insecure output handling, data leakage through retrieval pipelines, and OWASP Top 10 for LLM Applications.
Be familiar with reverse engineering or vulnerability research.
Have experience in a compliance-bound setting, such as FedRAMP, SOC 2, or ISO 27001.
Hiring Policy
This job description may be revised over time.
Application Security Engineer
The Company
ISA Consulting delivers end-to-end Digital Transformation, Digital Consulting, and Business Process Services solutions across all Tech Stacks. The company serves clients from numerous industries and business verticals. Its teams include Full Stack Developers, Data Engineers, Architects, Project Managers, Quality Analysts, and Strategists working across several time zones.
Job Summary
ISA Consulting seeks an Application Security Engineer to support the security of its eDiscovery and AI platform throughout the software development lifecycle. This position centers on manual secure-code reviews, application-security testing, and collaboration with engineering teams to identify and remediate vulnerabilities before production release. The work is practical and technically diverse, involving code reviews across different products, languages, and frameworks; full ownership of reviews; and development of supporting tools and automation. The successful candidate will communicate technical matters effectively, work autonomously, prepare clear evidence-supported findings, and collaborate with engineering through remediation.
Responsibilities & Duties
Code Review & Assessment
Conduct detailed manual, tool-supported, and AI-supported code reviews to detect vulnerabilities prior to release.
Take responsibility for assigned reviews from initial scoping and repository discovery through documented findings and remediation follow-up.
Address blockers independently or escalate them when needed, while engaging engineering teams without daily supervision.
Prepare comprehensive, evidence-based review reports containing severity classifications, reproduction information, and remediation recommendations; track these in Jira until closure against established SLAs.
Work with engineering teams to assess and resolve findings produced by code reviews, SAST/DAST, and other assessment tools.
Security Engineering & SDLC
Support security assessments for new products, features, and services.
Advise on secure design, architectural, and implementation choices.
Use secure development lifecycle methods, including threat modeling and security testing.
Manage dependency and supply-chain risks, including SCA, SBOM, and vulnerability triage, and help expand security controls within CI/CD pipelines.
Collaborate with Security Operations and Infrastructure teams on security tools and automation.
Influence & Enablement
Develop understandable security guidance and documentation for engineering teams.
Support security training initiatives and the Security Champions program.
Requirements & Skills
Act as a professional example and encourage professional conduct.
Demonstrate outstanding written and spoken communication abilities when working with people across disciplines and organizational levels.
Be prepared to contribute to several projects, assignments, and IT competency areas.
Maintain an open-minded, solution-focused approach.
Show strong diagnostic and problem-solving abilities.
Be committed to providing an exceptional customer-service experience for all employees.
Education & Experience
Hold a Bachelor's degree in a relevant discipline such as Computer Science, Software Engineering, Security, or similar, or possess an equivalent mix of education, training, and experience.
Have at least 3-5 years of professional experience in application security or software engineering, including a minimum of 2 years focused on secure code review, application security testing, or secure development.
Possess practical software-development experience adequate for reading and reasoning about production code.
Have professional experience carrying out security assessments, including manual secure-code reviews.
Have professional experience creating or evaluating threat models.
Be experienced with SAST, DAST, and SCA tools, such as Semgrep, CodeQL, Burp Suite, and Dependency-Track.
Be able to read and assess unfamiliar codebases in several languages, including C#/.NET, Node/TypeScript, Java, Python, and Ruby.
Understand the HTTP protocol, web frameworks, and web and cloud architectures.
Understand cryptography in application code, including key handling, secrets management, and encryption in transit and at rest.
Be familiar with multi-tenant SaaS security, especially tenant isolation and access control.
Have used AI-assisted tools such as Claude Code and Copilot for code-review or triage workflows.
Know LLM/GenAI application-security topics, including prompt injection, insecure output handling, data leakage through retrieval pipelines, and OWASP Top 10 for LLM Applications.
Be familiar with reverse engineering or vulnerability research.
Have experience in a compliance-bound setting, such as FedRAMP, SOC 2, or ISO 27001.