Back to search
Trendyol Group Linkedin · Posted 14d ago

AppSec - Vulnerability Management Engineer

Istanbul

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

About the job

About the Team

At Trendyol Tech, our mission is to create a positive impact in our ecosystem by enabling commerce through technology.

We solve complex problems with data, creativity, and agility — always driven by real outcomes. With a culture built on learning, collaboration, and ownership, we grow together while building what’s next.


About the Role

As an Application Security Engineer, you’ll work closely with Trendyol’s engineering teams to enhance application security across our platforms. You’ll perform web and mobile security testing, validate fixes through code reviews, and provide expert guidance on secure coding practices. In this role, you’ll support our bug bounty program, develop custom security tools, and help drive root-cause analysis and remediation. We’re looking for a collaborative, open-minded teammate who is eager to improve, communicate clearly, and promote security best practices throughout the organization.



Your Main Responsibilities:

  • Ability to work collaboratively in a team environment and is a friendly, humble, responsible teammate.
  • Be a subject matter expert and guidance to Trendyol Engineering for secure coding practices, application security.
  • Experience in performing web security testing on web applications and mobile applications.
  • Ensuring to confirm of the fix of the vulnerability by making manual code review on the relevant commit.
  • Experience identifying and protecting against web application and web-service security vulnerabilities including those found in the OWASP Top 10.
  • Experience in fixing vulnerabilities, documenting and remediation guidance for discovered vulnerabilities.
  • Developing custom security tools and security rules(e.g. Semgrep / Nuclei)
  • Promoting security best practices among developers.
  • Ability to conduct root cause analysis against vulnerabilities and determine feasible technical solutions.
  • Managing Bug Bounty Platform.


Qualities We Are Looking For:

  • Experience with multiple programming/scripting languages (such as, Java, Golang, Python etc.)
  • Having excellent communication skills.
  • Experience with vulnerability management and enterprise remediation efforts.
  • Being an Agile minded team player.
  • Eagerness on self-improvement, open-minded, future-oriented.
  • English language skills for reading technical documentation and to fix the vulnerabilities with international developers.
  • Professional certification (e.g. eWPT, eWPTXv2, OSWE, eMAPT, GWAPT) preferred.
  • Familiarity with front-end and back-end web application frameworks (i.e. Spring, Gin, React, etc).
  • Bonus points for community contributions like public CVEs, bug bounty recognition, blogs, etc.




Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search