
About this role
Description
Atera is leading the future of IT with the world’s first Autonomous IT platform, with built-in AI agents. At its core is IT Autopilot, functioning as a personal IT professional for every employee, and AI Copilot, an IT technician’s companion designed to boost productivity and efficiency. The full-stack platform unifies RMM, ticketing, help desk, patch management, and all essential IT operations into one secure, scalable solution. Trusted by 13,000+ customers in 120+ countries, Atera helps organizations scale, boost service quality, and turn IT into a driver of lasting business growth.
What You Will Do
As an Application Security Engineer, you will act as a bridge between offensive security and engineering teams. You will leverage your penetration-testing mindset to proactively improve the security of applications throughout their lifecycles. This includes partnering with developers to identify and remediate vulnerabilities, contributing to secure design decisions, participating in threat modeling, and conducting security reviews. You will help build scalable, repeatable security practices that reduce risk across the product.
Responsibilities
- Validating and prioritizing vulnerabilities from PTs, bug bounties, and tools
- Collaborating with engineering teams on remediation
- Participating in application security reviews
- Supporting Secure Software Development Lifecycle (SSDLC)
- Managing and using SAST, DAST, and SCA tools
- Developing security standards and best practices.
Requirements
Requirements:
- 3–5 years of hands-on experience as a Penetration Tester (Web and API)
- Strong expertise in performing manual penetration testing (not tool-only)
- Deep understanding of OWASP Top 10 and OWASP Top 10 for LLM
- Ability to read and understand code in C#, JavaScript
- Knowledge of OWASP ASVS (Application Security Verification Standard)
- Strong communication skills with developers
- Strong English proficiency (written and spoken)
- Familiarity with cloud environments (AWS, Azure, or GCP)
- Experience with bug bounty programs or Red Team activities (advantage)
- Experience performing Application Security Reviews (advantage)