Role Overview
We are looking for a seasoned Senior Application Security (AppSec) Engineer to specialize in code review with a strong focus on Python web security. This role is crucial in ensuring our applications are secure and follow best practices, particularly through reviewing and analyzing code in a demo environment.
Responsibilities
- Conduct thorough code reviews to identify potential security vulnerabilities.
- Focus on web security, particularly with frameworks and libraries such as FastAPI, Starlette, SQLAlchemy, and Jinja2.
- Analyze and review authorization and access controls, with attention to role/group permissions and row-level access.
- Produce a detailed written report with specific file and line references to highlight findings and recommendations.
- Work independently and directly, without subcontracting, in a demo environment using synthetic data.
- Sign a non-disclosure agreement (NDA) as part of the engagement.
Required Skills
- Extensive experience in Python web security, specifically with FastAPI, Starlette, SQLAlchemy, and Jinja2.
- Expertise in reviewing source code to assess security posture and implementing improvements.
- Strong ability to produce comprehensive reports detailing code review findings.
Nice to Have
- Previous experience working with synthetic data in controlled environments.
- Familiarity with various authorization models and best practices in access control.
- Experience with Alpine.js