Cybersecurity Application Security Engineer
On-siteBelgrade, Central Serbia, Serbia
Job Summary
Review source code and application architectures to identify and communicate security vulnerabilities to development teams. Drive the adoption of Software Bill of Materials (SBOM) for supply chain visibility and license compliance. Implement automated Software Composition Analysis (SCA) to remediate vulnerabilities in third-party libraries. Develop and support automated security tooling and agentic workflows within CI/CD pipelines to streamline vulnerability triage and threat modeling. Work closely with the penetration testing team to implement remediations for identified security vulnerabilities. Support the implementation of security configurations and countermeasures based on emerging threats. This role bridges security and engineering to foster a secure-by-design culture within Rivian's Enterprise Cybersecurity team, emphasizing software supply chain integrity.
Required Qualifications
- 4+ years of application security experience
- Proficiency with GraphQL
- Proficiency with AWS
- Proficiency with React
- Proficiency with Java
- Proficiency with Node.js
- Proficiency with Python
- Proficiency with containerization technologies like Docker and Kubernetes
- Hands-on experience with reviewing and remediating common SAST and SCA vulnerabilities
- Strong hands-on coding or scripting skills (e.g., Python, Go) for building security utilities and automation
- Strong problem-solving and decision-making capabilities
Desired Qualifications
- Experience in the automotive, manufacturing, or technology industries
- Experience with cloud native (AWS preferred) and Kubernetes hosted applications
- Experience with Gitlab CI/CD or other popular DevOps technologies
- Experience identifying and mitigating AI-specific vulnerabilities
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.