Job description
Contract Details
-
Location: Luxembourg – 100% on-site (non-negotiable)
-
Eligibility: European nationality mandatory
Assignment Overview
A long-term engagement is available for an experienced Application Security / Vulnerability Analyst to support application security testing activities for large-scale, enterprise-grade environments. The role focuses on early identification of security vulnerabilities in web and mobile applications through secure code review, static analysis, dynamic testing, and penetration testing.
Key Responsibilities
-
Execute end-to-end application security testing for web and mobile applications
-
Perform secure code reviews and penetration testing
-
Conduct static and dynamic application security assessments
-
Prepare and maintain custom scripts, automations, and integrations
-
Draft playbooks, technical documentation, and security testing reports
-
Present findings to technical and management stakeholders
-
Develop and maintain testing tools, automation, and proof-of-concept exploits
-
Coordinate with internal teams and external stakeholders to ensure effective delivery
Mandatory Skills & Experience
-
Minimum 7 years of experience in web application vulnerability assessment, including secure code review
-
Minimum 10 years cumulative experience in software development using Python, .NET, and Java
-
Strong hands-on expertise with OWASP Testing Methodologies
-
Proven experience in Web and Mobile Application Pentesting
-
Advanced scripting capabilities and ability to develop custom testing tools
-
Experience with enterprise Application Security Testing tools, including (but not limited to):
-
Fortify (SSC / SCA)
-
Veracode
-
Snyk
-
OWASP Dependency Check
-
Burp Suite
-
Sonatype Lifecycle
-
-
Ability to adapt to fast-evolving application security technologies
-
Strong analytical and problem-solving skills
-
Excellent communication skills with both technical and non-technical audiences
-
Ability to produce clear, structured technical reports
Education
-
Graduate degree (minimum required)
(Computer Science, Information Technology, or related discipline preferred)