Find a job

Associate Application Security Testing Engineer - 2915


Associate Application Security Testing Engineer

  • Primary Location:
    Cluj - Napoca
  • Contract Type:
  • Employment Basis:

3 extra days of vacation


Internal International Opportunities

Health insurance

Mobile allowance

Choose your Operating System

Learning and Development

Fully provisioned kitchen

Share this page
Share with linkedin
Share with facebook
Share with twitter
Share with email

The Paddy Power Betfair Cyber Security Team is a wide security team, with +60 people, covering a large spectrum of security areas of expertise. Its goal is to provide and ensure that proper security controls are protecting against risk across all businesses within the group. The successful candidate will be part of the Application Security Testing Team and will have the opportunity to use technical skills and knowledge to identify new vulnerabilities and contribute to PPB overall security posture.

The Application Security Tester acts as an enabler for the wider Security Team, and aims to ensure the adoption of Application Security practices, detection of security vulnerabilities and mitigations are acted upon the project lifecycle.

You'll be performing penetration testing for internal components and third-party applications that are used by the company. The overall scope will be mainly web applications.

The role involves a collaborative approach in the engagement phase, where you'll be gathering all required information for the pentest and clearly defining the scope with the stake holders. It also includes close collaboration with development and infrastructure teams, not only to ensure that the identified vulnerabilities are validated and understood, but also to test the provided patches against other attack vectors.


In sum, you'll be leading web applications security assessments, including the engagement phase, code review, penetration test, vulnerability reporting&tracking, patching recommendation and support.


What We're Looking For…

  • Technical skills to test and review code of applications developed internally and externally, in line with application security best practices, by tracing the execution flow through an application and identifying possible security vulnerabilities or areas of weakness;
  • Motivation and soft skills to proactively unblock pentest requirements, engaging with different stakeholders (technical and non-technical) including developers, product owners and managers;
  • Experience and ability to elaborate self-explanatory penetration testing reports, with high quality level, capable of being clearly understood by teams that don't have security knowledge;
  • Wide security knowledge to provide recommendations to the development teams on how to fix/mitigate a security vulnerability on applications and systems;
  • Motivation and proactivity to lead security awareness/training initiates delivered by AppSec for developers, namely organizing CTFs and Show&Tells;
  • Motivation and proactivity to keep up with the latest offensive techniques, promoting self-improvement of soft and technical skills.

We'd love to see…

  • Good written and verbal communication skills;
  • A team player, who strives to maximize team and departmental performance;
  • Resolves and/or escalates issues in a timely fashion;
  • Knowledge sharing and interest in expanding other team members security skills and mindset;
  • Capability to focus and work without supervision.


Ways of working:

Flexible working is our way of working! We're a diverse workforce and therefore a 'one size fits all' approach isn't necessarily best. Whatever your personal needs may be, let's have a chat and see how we can accommodate them;
We thank all applicants for their interest, however only the suitable candidates will be contacted for an interview.

By submitting your application online, you agree that: your details will be used to progress your application for employment. If your application is successful, your details will be used to administer your personnel record.If your application is unsuccessful, we will retain your details for a period no longer than two years, in order to consider you for prospective Paddy Power Betfair role.

Close map
Cluj - Napoca
Blvd. 21 Decembrie 1989, no. 77, The Office building, Betfair Romania Development, Entrance A, 4th Floor, Cluj, Romania, 400124

This is who we are

Blip is a Tech and Innovation Hub with a strong knowledge in software development, mobile apps, web platforms and retail applications for betting and gaming.

We are part of Flutter Entertainment – one of the World´s Largest Groups in the bookmaking industry, with an annual revenue of around 2 billion euros. The Code we develop, powering brands such as PaddyPower, Betfair and Fanduel, is used by over 5 million people in more than 100 countries and we are in the API Billionaire Club alongside players such as Google, Facebook and Twitter.

The Missing Piece

At Blip people always come first, that’s why we believe we can complement each other. You are our missing piece to be a better company, to build a better business for everybody, including ourselves.On the other hand, we are your missing piece, giving you the flexibility, work life balance and the tech challenge you´re lacking.
It all starts here!

This is your Challenge

  • Delivering product at scale for over 5 million customers, 99,9% of transactions in less than a second
  • Our systems process more than 7 million transactions every day (more than all the European stock exchanges combined)
  • Deliver high transitional products, serving more than 2.5Bn calls a day
  • Diverse and up to date technical landscape to explore, leverage and innovate
  • The products you’ll develop will comply with ambitious uptime targets: less than 50 minutes downtime expected per year
  • Continuous Integration, Deployment and Testing