Growe Talents logo
Growe Talents
Company insights
Anywhere
Posted August 14, 2026 · 18 days ago · Last seen September 1, 2026 · Est. expiry September 18, 2026

Application Security Engineer

Application Security Engineer / Penetration tester
How this salary compares
Salary Context: Application Security Engineer

Hover or tap a row for full statistics (EUR / month on this chart).

Salary analysis

Compared with the selected benchmark ("All roles in Anywhere"), this listing's salary midpoint is about 93% lower. The offer sits below the benchmark range (€7,424–€22,408). The listed pay band (€789–€1,353) is tighter than the benchmark, which suggests lower salary variability. This benchmark is based on 2 comparable listings.

Monthly salary comparison for Application Security Engineer
MarketLower bound (25th percentile)MedianUpper bound (75th percentile)
Market Average: Application Security Engineer€9,404/per month€12,587/per month€15,770/per month
All roles in Anywhere€7,424/per month€15,508/per month€22,408/per month
About the role

Our client, Growe, is a leading business advisory and services group in iGaming and Entertainment. Сreators of strategies that work and solutions that scale. Combining strategic vision with hands-on expertise, Growe helps businesses navigate the fast-evolving industry, seize new opportunities, enter new markets, and achieve sustainable growth. Perfect for those who aim to: Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation; Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production; Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws; Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorization, and business logic. Experience you’ll need to bring: 3 years of experience in Application Security, Product Security, or Penetration Testing; Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner; Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec; Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment; Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures; Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC); Ability to identify complex authorization bypasses, session management flaws, and business logic bugs; Ability to read and analyze modern application code to spot security flaws (will be a plus); Basic understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals (will be a plus); Intermediate level of English (spoken and written). It's a perfect match if you have those personal features: Strong communication skills to effectively collaborate with engineering, product, and DevOps teams; Result-oriented mindset; Openness to learning. Our clients offer competitive benefits to support your professional and personal growth, including: Health & Wellness Focus; Global Medical Coverage; Growth Opportunities; Benefits Programs (compensation for the gym/stomatology/psychological service & etc.); Performance-Driven Rewards; Dynamic Work Environment. Apply, and let your growth journey begin.

Job Details

Responsibilities

  • Triage, validate, and prioritize security findings from SAST, SCA, and secret scanning tools
  • Conduct manual and tool-assisted code reviews to identify vulnerabilities and insecure implementations
  • Perform hands-on penetration testing of web apps, microservices, and APIs
  • Audit REST and GraphQL APIs and web apps focusing on core security risks, authentication, authorization, and business logic

Requirements

  • 3 years of experience in Application Security, Product Security, or Penetration Testing
  • Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner
  • Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec
  • Deep understanding of OWASP Top 10 vulnerabilities and OWASP API Security Top 10 for REST/GraphQL
  • Knowledge of identity protocols and access control (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC)
  • Ability to read and analyze modern application code
  • Cloud security basics in AWS and Kubernetes are a plus
  • Intermediate English

Skills & Technologies

SASTSCASecret scanningBurp SuiteNucleiSubfinderSQLmapMetasploitOAuth 2.0OIDCJWTSAMLRBAC/ABACOWASPKubernetesAWS
Seen 8 hours agoPartial Schema
Growe Talents logo
Growe Talents
View company

Help us improve JobCrawls — sign in to sync saved jobs across devices, or send feedback anytime.