الوصف الوظيفي
Security that arrives only after launch is already late.
ErthDev is looking for an Application Security Engineer to help teams build secure software throughout the development lifecycle.
You'll partner with engineers on threat modeling, secure design, code review, and remediation—not only end-of-project audits.
What you'll do
- Embed security practices into design and development.
- Perform application security reviews and threat modeling.
- Help teams remediate vulnerabilities with practical guidance.
- Improve secure coding standards and checklists.
- Support dependency, secret, and CI security controls.
- Collaborate with penetration testers and engineering leads.
- Review authentication, authorization, and data-handling designs.
- Educate teams through clear examples and reviews.
- Assess third-party and integration security risks.
- Contribute to incident response readiness for application issues.
AppSec at ErthDev
Penetration testing finds what slipped through.
AppSec reduces how often things slip through in the first place.
We want security as part of engineering, not a final gate.
What you'll get
- Fully remote work from Egypt
- Flexible working hours with collaboration overlap
- Cairo office access when needed
- Paid annual leave and sick leave
- Performance bonuses and annual salary reviews
- Learning and development support
- Courses and certifications
- Conference opportunities
- Equipment and internet support
- Medical insurance
- Mentorship and career growth
- Exposure to projects across different industries
Hiring process
Application → Initial Conversation → Practical Assessment → Technical Interview → Final Conversation → Offer
If your instinct is to prevent vulnerabilities—not only report them—we'd like to hear from you.
Apply through LinkedIn Easy Apply or the ErthDev careers page.
المتطلبات
What we're looking for
- Strong understanding of web and API security.
- Experience with secure development practices.
- Familiarity with OWASP guidance and common vulnerability classes.
- Ability to review code and architecture for security risk.
- Clear communication with developers.
- Practical remediation mindset.
- Understanding of CI/CD security tooling.
- Ability to prioritize risk rather than chase every finding equally.
Experience with SAST/DAST, dependency scanning, cloud security basics, identity systems, and secure SDLC programs is a plus.