FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Tech Stack
Tools & technologiesJavaScriptNode.jsNoSQLReactSQLTypeScript
About the role
Key responsibilities & impact- Review and validate security vulnerabilities identified in React, TypeScript, JavaScript, and Node.js code
- Trace vulnerabilities from source code in Bitbucket through API calls, browser behavior, and deployment configurations
- Implement fixes for vulnerabilities in front-end and Node.js applications
- Use AI to analyze large codebases
- Work with security controls for AI agents capable of interacting with enterprise systems
- Create unit, integration, end-to-end (E2E), and security regression tests
- Re-run security scans and provide evidence to close vulnerabilities in Jira, Security Workbench, Archer, or equivalent systems
- Collaborate with developers and Product, AppSec, QA, DevOps, and Platform Security teams
- Identify recurring vulnerability patterns and create reusable secure development guidance or automated fixes
- Improve security controls in pull requests, branch policies, build pipelines, and release gates
- Investigate false positives and document risk-based decisions when remediation cannot be completed immediately
- Support security reviews, penetration testing, incident-related remediation, and vulnerability trend monitoring
Requirements
What you’ll need- Strong experience securing Node.js services, APIs, and Backend-for-Frontend (BFF) applications
- Knowledge of React components, hooks, context, routing, state management, and SSR where applicable
- Knowledge of securely handling user-controlled data in components, forms, URLs, query parameters, and client-side state
- Ability to analyze pull requests, branches, commit history, and repository configurations
- Familiarity with XSS, dangerouslySetInnerHTML, DOM-based XSS, client-side open redirects, browser storage, source maps, CSP, authorization controls, data leakage, and dependency/software supply chain vulnerabilities
- Knowledge of secure SQL and NoSQL queries, command execution, uploads/downloads, path and URL parameters, HTTP headers, serialization/deserialization, sessions/tokens, and SSRF
- Experience with Checkmarx, Veracode, Fortify, SonarQube, Snyk Code, or Semgrep
- 5+ years of experience in front-end or full-stack software engineering
- 3+ years working directly with application security, secure coding, or vulnerability remediation in DevSecOps environments
- Strong experience with React, TypeScript, JavaScript, Node.js, HTML, CSS, and HTTP
- Experience with Git and Bitbucket in enterprise environments
- Proven experience tracking vulnerabilities from identification through remediation and closure validation
- Experience with web applications that handle sensitive data
- Ability to work with application, security, QA, DevOps, and infrastructure teams
- Advanced English proficiency for daily communication
- Nice to have: experience with AI assistant/agent security, AI agents for development, agentic platforms, LLM security, GitHub/GitLab, information security research, security automation, and using AI to discover and remediate vulnerabilities
Benefits
Comp & perks- Work arrangement: 100% remote
- Meal and/or food allowance
- Well-Being Program: psychological, legal, social, and financial support
- Health and dental insurance
- Life insurance
- Wellhub
- Discount partnerships with Sucesu, Target Trust, Sesc, and Seprorgs
- Company anniversary bonus
- Employee referral bonus for successful hires
- Childcare assistance
- CLT employment contract, 44 hours per week
