Security Engineer

Istanbul, Turkey
Security /
Full-Time /
Remote
Before jumping in on all the information about the role and what you can bring to the table, let us introduce ourselves real quick.

About us

Hi there! We are Insider, a B2B SaaS company that drives growth for its clients around the world. How are we achieving this? We are connecting data across channels, predicting future behavior with AI, and individualizing experiences from a single platform with the fastest time to value.

We announced that we unlocked our unicorn status after our Series D round. We are backed by top-notch investors including Sequoia Capital, QIA, Riverwood, Endeavor Catalyst and trusted by 1000+ brands from high-growth startups to the most prestigious Fortune 500 companies such as Singapore Airlines, Virgin, Nestle, Nissan, Samsung, Lenovo, Puma, MediaMarkt, IKEA, Allianz, Santander, Dominos, Avon, CNN, and the list goes on.

We are the #1 Leader everywhere! We are recognized as a leader in The Forrester Wave™ for Cross-Channel Campaign Management in Q3, 2021. We are also named a leader in 2021 Gartner® Magic Quadrant™ for Personalization Engines. But wait, there is more. For 21 quarters in a row, we’ve been ranked as a leader in G2 Mobile Marketing, Personalization, Customer Data Platform, and Customer Journey Analytics Grids.
We are also proud to become one of the very few female-led B2B SaaS unicorns in the world.

Behind all these achievements, there is an exceptionally talented and passionate team across 28 countries that moves fast and agile, creates cutting-edge products, and focuses on making an impact. If you want to join us in this journey, just keep reading.

And now? Now we are looking for a Security Engineer who wants to take their career one step further. If you think you are one of those people, here you will have the chance to work with the world's leading brands with Artificial Intelligence & Machine Learning technologies. Right now, while you are reading this, we are sending an average of 2.2 billion requests and almost 2 billion instant notifications to more than 450 servers a day. On the Artificial Intelligence and Predictive side, we have more than 100 TB of historical data. We do not wait for jobs or opportunities to come to our feet, we create them. We have now reached 25% of global users. If all these interests you, read on for more!

Our Engineers and Software Developers always think with an innovative perspective, taking advantage of the inexhaustible power of the digital world. They create impressive and intelligent products like a true artist. Our Product and Development teams are located in our Istanbul office, so we produce and develop the technology we export to the world in our own country. As Insider, we believe in cooperation and adapting the innovations brought by technology by acting fast. We work closely with other Departments with agile teams, and we are not afraid of getting our hands dirty. As we said; we do not wait for jobs or opportunities to come to our feet, we create them ourselves. You can check our Tech Stacks here!

A Security Engineer in Insider day in and day out:

    • performs web, mobile application, and internal penetration test, source code reviews, threat analysis, social-engineering assessments,
    • monitors security tools and take action in response,
    • researches new attack vectors and stay current with cybersecurity news and trends,
    • trains Quality Assurance and Development teams in standard security testing techniques.

We want you to join us while we are taking a step into the future if you:

    • have 2+ years of working experience in web application security,
    • have hands-on experience in security testing of Web applications, Web service, Mobile applications, APIs, etc.
    • have experience securing REST APIs and web services,
    • have experience using and implementing SAST / DAST tools such as Fortify, Veracode, Checkmarx, or other similar tools,
    • have familiarity with software library vulnerability scanning and tracking tools such as BlackDuck, Whitesource, and so on,
    • know conducting penetration tests of information systems using commercial and open-source exploitation tools,
    • have a good understanding of standard security vulnerabilities and common remediation as published by OWASP, SANS, etc.
    • have experience working with secure coding methodology and best practices and their implementation within engineering teams,
    • will support developers of our business units in their SDLC and provide guidance regarding mitigations to emerging threats,
    • will review application source code based on static application security testing tools,
    • will be engaging in security research to remain current on vulnerabilities and testing tools,
    • will be creating detailed, professional documentation/reports that clearly communicate vulnerabilities, mitigation strategies, and remediation steps,
    • have the ability to work on multiple projects concurrently and be committed to providing exemplary customer service,
    • have experience with obtaining access through spear-phishing,
    • have strong written and verbal communication skills in English,
    • have Python, Javascript, PHP programming experience as a plus,
    • have knowledge in scripting (any language) and experience in automation scripts for application security testing as a plus,
    • have familiarity with cloud security, particularly AWS Security concepts as a plus,
    • have certifications of CEH, eWAPTx, OSCP etc. as a plus,
    • are able to work in a team-centric environment,
    • have strong critical thinking and analytical skills,
    • have experience in drafting technical manual, installation manuals, procedure outlines and incident response plans in order to enhance system security documentation,
    • have experience in executing white, gray or black box security posture assessments and complete detailed reports that outline the findings and recommendations,
    • have strong presentation, written and oral communication skills.

While exporting our technology to the world, we offer you:

    • “Tech Talks” with famous and groundbreaking people from the software world, “Dev Talks” where our Software Developers talk about their career steps, and many events where groundbreaking ideas are discussed,
    • Hackathons we organize inside that push the boundaries, programming challenges, and coding competitions,
    • Free access to exclusive services such as Laracast, Egghead, LinkedIn Learning, Blinkist, Masterclass, and Spotify
    • Shareowner System that we offer to all Insiders who meet certain criteria
    • Inclusive Private Health Insurance
    • Multinet to cover food expenses covered on a monthly basis
    • Team Activities that are bursting with fun,
    • No Dress code! This is a fast and innovative startup, you can wear whatever you want.
We provide equal opportunity in a zero-discrimination workplace and not just welcome but also embrace everyone without regard to sex, race, color, nationality, religion, gender identity, sexual orientation, disability status, citizenship, or marital status.

Please follow Insider on LinkedIn, Instagram, Youtube, and Medium!