Join to apply for the
Senior Application Security Engineer
role at
Acronis
Acronis is revolutionizing cyber protection—providing natively integrated, all-in-one solutions that monitor, control, and protect the data that businesses and lives depend on.
We are looking for a Senior Application Security Engineer to join our mission to create a #CyberFit future and protect all data, applications and systems across any environment.
The application security team works to make Acronis applications more secure against all kinds of threats.
You will work with good guys on responsible disclosure, find security bugs before bad guys do it, change development processes to prevent bugs, monitor attacks and respond, and create novel solutions to detect and protect applications.
What You’ll Do
Threat modeling: Think about how attackers can compromise a system and what protections are needed.
Secure Software Development Lifecycle: Help developers write secure code that minimizes vulnerabilities by implementing secure coding standards, techniques, and best practices.
Security code reviews: Identify security vulnerabilities in source code before an application is deployed to production.
Vulnerability testing and analysis: Discover weaknesses once an application is deployed and advise development teams on remediation.
Conduct security assessments for software components developed in the company.
Validate external security reports and bug bounty submissions.
Take part in the SLDC process development and implementation.
Conduct post-mortem reviews of application security bugs.
Consult engineers on application security matters and train them on secure development practices.
What You Bring
Understanding of security models of Web/REST API, cloud, mobile and desktop apps.
Hands on experience with security assessment tools and attack techniques.
Code assessments in programming languages Go, Python, Ruby, C/C++, JavaScript.
Basic programming skills with Go, Python or another language will come handy.
Strong communication skills.
2+ years in Application Security.
Strong knowledge of the modern web, mobile, and network security.
Published security research, open source tools, blog posts, proven history of bug bounty programs participation considered a strong advantage.
Please be ready to answer in an interview the following questions:
What is the Same Origin Policy?
Share your knowledge about Cross-site scripting contexts.
Describe any attack like SQL injection, XXE, SSRF, or any other.
Suggest right fixes and possible bypasses.
(Windows Security) Your opinion about LPE from Admin to the System user.
How to count possible compromised accounts?
Be ready to write a simple exploit or a few lines of code that allows checking some kind of attacking vector.
Who We Are
Acronis is a global cyber protection company that provides natively integrated cybersecurity, data protection, and endpoint management for managed service providers (MSPs), small and medium businesses (SMBs), enterprise IT departments and home users.
Our all-in-one solutions are highly efficient and designed to identify, prevent, detect, respond, remediate, and recover from modern cyberthreats with minimal downtime, ensuring data integrity and business continuity.
We offer the most comprehensive security solution on the market for MSPs with our unique ability to meet the needs of diverse and distributed IT environments.
Interview Practices
To maintain a fair and genuine hiring process, we kindly ask that all candidates participate in interviews without the assistance of AI tools or external prompts.
Our interview process is designed to assess your individual skills, experiences, and communication style.
We value authenticity and want to ensure we’re getting to know you—not a digital assistant.
To help maintain this integrity, we ask to remove virtual backgrounds and include in-person interviews in our hiring process.
Acronis is an equal opportunity employer.
All qualified applicants will receive consideration for employment without regard to age, ancestry, color, marital status, national origin, physical or mental disability, medical condition, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, gender identity or expression, or any other characteristic protected by applicable laws, regulations and ordinances.
#J-18808-Ljbffr