hirly

CCBill

Application Security Engineer

Remote

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at CCBill first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.5M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Role family
Engineering
Seniority
Mid level
Country
RS
Work mode
Remote-friendly
First seen by hirly
15 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

CCBill is an online payment services provider used by more than 30,000 websites globally that supports the needs of both new and established businesses in the e-commerce and online space.

We are seeking an Application Security Engineer to support the secure development of internally developed applications. The successful candidate will perform application security testing, code reviews, threat modelling and vulnerability assessments while supporting the integration of security controls into the software development lifecycle.

The role will work closely with the development, architecture and Information Security team to identify and remediate security risks and improve the overall security posture of applications.

Location: Serbia

Working Hours: Monday to Friday (40 hours); 1PM-9PM CET, fully remote

Key Job Requirements:

Application Security Testing:

Perform manual and automated security assessments of web applications and APIs.

Conduct application penetration testing to identify vulnerabilities, security weaknesses and configuration issues.

Document findings, remediation recommendations and risk ratings in clear technical reports.

Validate remediation activities through re-testing

Secure Development:

Participate in threat modelling exercises and security design reviews.

Perform security-focused source code reviews of internally developed applications.

Support developers in understanding and remediating identified vulnerabilities.

Promote secure coding practices and security awareness across development teams.

DevSecOps and Security Automation

Support the implementation and operation of security testing within CI/CD pipelines.

Assist with the deployment and tuning of:

Static Application Security Testing (SAST)

Dynamic Application Security Testing (DAST)

Software Composition Analysis (SCA)

Secrets detection controls

Contribute to security automation initiatives using Jenkins, GitLab and Bitbucket.

Vulnerability Management

Track and manage vulnerabilities identified during security testing activities.

Work with development teams to prioritise and remediate findings.

Assist in assessing application security risks and recommending appropriate mitigation measures.

Collaboration

Work closely with development, architecture, infrastructure, and Information Security teams to improve application security.

Support security reviews prior to production deployments.

Contribute to the continuous improvement of application security standards, processes and procedures

Key Skills & Qualifications:

Required

Minimum 3 years of experience in application security, penetration testing, software development or a related information security role.

Experience performing web application security assessments and penetration testing.

Understanding of secure software development practices.

Experience reviewing source code and identifying common security vulnerabilities.

Strong knowledge of:

OWASP Top 10

CWE

NIST security guidance

Secure coding principles

Technical Skills

Knowledge of web technologies, APIs, databases and networking concepts.

Familiarity with programming languages such as:

Java

.NET/C#

Python

JavaScript

Perl

Understanding authentication, authorisation and session management concepts.

Tools

Experience with some of the following:

Burp Suite

OWASP ZAP

Nessus

Metasploit

Wireshark

SAST and DAST tools

CI/CD and DevSecOps

Exposure to:

Jenkins

GitLab

Bitbucket

Agile development environments

Personal Attributes

Strong analytical and problem-solving skills.

Effective verbal and written communication skills.

Ability to work collaboratively within cross-functional teams.

Willingness to learn and develop expertise in application security and DevSecOps practices.

Proactive, strategic thinker who can turn concepts into actionable plans.

Advocates security improvement initiatives while understanding business priorities and constraints.

Demonstrated experience in mentoring, coaching, and supporting the growth of a diverse and distributed team.

Original posting on CCBill's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job