Vilnius

Security Specialist

Our client is a fast growing compliance startup which offers a complete compliance management suite for all ‘know your customer’ requirements in the financial services and other sectors that wish to provide their services in the cyberspace. The company’s platform provides an integrated solution that is banking-core friendly and that spans both photo and live video identity verification, data monitoring, screening, due-diligence, risk scoring and case management.

As a Security Specialist, you will work closely with their engineering, DevOps, and product teams to ensure security is embedded throughout the development lifecycle. Your role will combine technical expertise with a practical understanding of secure development practices.


Key Responsibilities:

  • Collaborate with product and engineering teams to integrate security best practices into the SDLC (secure development lifecycle);
  • Perform periodic penetration tests, vulnerability assessments, and threat modeling;
  • Monitor and evaluate application and infrastructure security posture regularly;
  • Identify security risks and weaknesses; recommend actionable improvements;
  • Lead security incident response and forensic analysis when needed;
  • Define and enforce security policies, standards, and tooling across teams;
  • Conduct internal security training and awareness sessions;
  • Assist in security audits and compliance-related efforts (e.g. ISO 27001, SOC 2);
  • Maintain and improve CI/CD pipeline security practices (e.g. SAST, DAST, secret scanning).

What They’re Looking For
Required Skills & Experience:

  • 3+ years of hands-on experience in application or product security;
  • Strong understanding of web application security principles (e.g. OWASP Top 10);
  • Proven experience in penetration testing or red teaming (manual and automated);
  • Proficiency in tools like Burp Suite, Nmap, Metasploit etc.;
  • Experience performing code-level reviews for security issues (.NET, JS/TS a plus);
  • Familiarity with secure DevOps and CI/CD pipeline security tooling;
  • Good understanding of authentication/authorization protocols (OAuth2, OpenID Connect);
  • Strong communication skills to translate technical risks to business impact.

Bonus Points for:

  • Certifications such as OSCP, CEH, CISSP, GWAPT, or CRTP;
  • Experience with cloud security in Azure, AWS, or GCP;
  • Knowledge of infrastructure-as-code and container security (e.g., Kubernetes, Docker);
  • Previous work with ISO 27001-certified environments.

Company offers:

  • Dynamic and supportive work environment with opportunity to grow together in a small and professional team of developers.
  • Possibility to make an impact for international business success and see your work results immediately.
  • Training culture: grow, develop your abilities and skills.

Monthly Salary:

From 3000 EUR gross