# Security Engineer

[Af](https://gurify.com/jobs?q=Af) · Ukraine · Posted 4 months ago

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://af.breezy.hr/p/4f04fcae4aed-appflame-security-engineer)

## Job description

appflame - Security Engineer
Company: AF
Location: UA
Type: FULL_TIME

appflame — Ukrainian product IT company that creates world-class products: Hily, Taimi, AdConnect, Mailkeeper, and more.

We are today:
• 7 years, 500+ employees, offices in Kyiv, London, Limassol, and Warsaw. Ranked 5th among the 50 best employers in Ukraine (Forbes 2025) and won in the “Place for Growth” category.
• Our apps Hily and Taimi are among the Top 5 dating apps in the U.S. with over 60 million users.

Our mission: Flame up the world with Ukrainian products. Our goal: Become a unicorn and turn Ukraine into a country where unicorns are born and thrive.

Role overview: You’ll focus on securing the SDLC, automating application security, developing anti-phishing initiatives, and building a strong security culture across all teams. You’ll work closely with Developers, DevOps, QA, and the Trust & Safety team to embed security throughout the development and delivery lifecycle.

You’ll also be the first security hire, with the opportunity to build a team and grow into a Head of Security role.

### In this role, you will:

- Build and implement Secure SDLC practices within the development process
- Integrate SAST, DAST, SCA, and other security tools into CI/CD pipelines
- Identify, analyze, and support the remediation of vulnerabilities in applications and dependencies
- Automate basic anti-phishing mechanisms and security controls
- Advise engineering teams on secure coding and security best practices
- Deliver security training and improve team awareness
- Participate in security monitoring and incident response
- Support the implementation of asset and risk management practices

### What we expect from you:

- 2+ years of experience in Product Security / AppSec / DevSecOps
- Experience with Secure SDLC or DevSecOps practices
- Familiarity with SAST, DAST, SCA, or other security scanning tools
- Experience working with CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, etc.)
- Hands-on experience using AI-driven security platforms to analyze vulnerabilities in code, dependencies, and cloud infrastructure
- Good understanding of OWASP MAS and common web and mobile vulnerabilities
- Experience building or improving risk management processes (risk assessment, SDLC integration, stakeholder visibility)

### Nice to have:

- Experience building AppSec / DevSecOps practices from scratch
- Experience with threat modeling or architecture security reviews
- Experience working with cloud platforms (AWS, GCP)
- Experience with Kubernetes and container security
- Participation in security incident response
- Relevant security certifications

Your journey: message from the recruiter > interview with manager > test> final interview > job offer.

Why appflame?

- Real Impact: Implement your ideas on a global scale with millions of users.
- No Barriers: Access to best practices from Snapchat, Meta, Google, and Apple.
- Growth Environment: We provide all resources to implement cutting-edge AI and automation.
- Care: We don’t leave our people alone with problems—professional or personal.

We provide all conditions for your talents to be fully revealed. We are loyal to our people. Our loyalty doesn’t fade at the end of the working day. We do not leave our people alone with their problems: neither professional nor personal.

Join us and flame up the world!

We are against all types of discrimination, bullying, and stereotypes. We provide equal employment opportunities regardless of race, skin color, religion, gender, sexual orientation, gender identity, age, marital status, health status or any other characteristics.

**Live in Af’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- TA [Cloud Security Engineer](https://gurify.com/job/cloud-security-engineer-at-tango-f1269c61ab1e) Tango · Warszawa, Poland · last week
- AW [Application Security Engineer (f/m/d)](https://gurify.com/job/application-security-engineer-f-m-d-at-awin-fb24719a88c0) Awin · Berlin, Poland · last week
- HA [Senior Security Engineer, Detection and Response](https://gurify.com/job/senior-security-engineer-detection-and-response-at-hackerone-45f09130ce13) Hackerone · London · last week
- ON [Application Security Engineer - ONE ZERO](https://gurify.com/job/application-security-engineer-one-zero-at-onezerobank-2e8386af9bda) Onezerobank · Tel Aviv-Yafo, Israel · last week
- AI [Senior Security Engineer, Detection & Response](https://gurify.com/job/senior-security-engineer-detection-response-at-aircallioinc-88e23520e0c1) Aircallioinc · San Francisco Office; Seattle Office · last week
- CO [Security Engineer](https://gurify.com/job/security-engineer-at-conduct-354c5d006329) Conduct · London, United Kingdom · last week

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Security Engineer","description":"\u003Cp\u003Eappflame - Security Engineer\u003Cbr /\u003ECompany: AF\u003Cbr /\u003ELocation: UA\u003Cbr /\u003EType: FULL_TIME\u003C/p\u003E\u003Cp\u003Eappflame \u2014 Ukrainian product IT company that creates world-class products: Hily, Taimi, AdConnect, Mailkeeper, and more.\u003C/p\u003E\u003Cp\u003EWe are today:\u003Cbr /\u003E\u2022 7 years, 500\u002B employees, offices in Kyiv, London, Limassol, and Warsaw. Ranked 5th among the 50 best employers in Ukraine (Forbes 2025) and won in the \u201CPlace for Growth\u201D category.\u003Cbr /\u003E\u2022 Our apps Hily and Taimi are among the Top 5 dating apps in the U.S. with over 60 million users.\u003C/p\u003E\u003Cp\u003EOur mission: Flame up the world with Ukrainian products. Our goal: Become a unicorn and turn Ukraine into a country where unicorns are born and thrive.\u003C/p\u003E\u003Cp\u003ERole overview: You\u2019ll focus on securing the SDLC, automating application security, developing anti-phishing initiatives, and building a strong security culture across all teams. You\u2019ll work closely with Developers, DevOps, QA, and the Trust \u0026amp; Safety team to embed security throughout the development and delivery lifecycle.\u003C/p\u003E\u003Cp\u003EYou\u2019ll also be the first security hire, with the opportunity to build a team and grow into a Head of Security role.\u003C/p\u003E\u003Ch3\u003EIn this role, you will:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EBuild and implement Secure SDLC practices within the development process\u003C/li\u003E\u003Cli\u003EIntegrate SAST, DAST, SCA, and other security tools into CI/CD pipelines\u003C/li\u003E\u003Cli\u003EIdentify, analyze, and support the remediation of vulnerabilities in applications and dependencies\u003C/li\u003E\u003Cli\u003EAutomate basic anti-phishing mechanisms and security controls\u003C/li\u003E\u003Cli\u003EAdvise engineering teams on secure coding and security best practices\u003C/li\u003E\u003Cli\u003EDeliver security training and improve team awareness\u003C/li\u003E\u003Cli\u003EParticipate in security monitoring and incident response\u003C/li\u003E\u003Cli\u003ESupport the implementation of asset and risk management practices\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWhat we expect from you:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E2\u002B years of experience in Product Security / AppSec / DevSecOps\u003C/li\u003E\u003Cli\u003EExperience with Secure SDLC or DevSecOps practices\u003C/li\u003E\u003Cli\u003EFamiliarity with SAST, DAST, SCA, or other security scanning tools\u003C/li\u003E\u003Cli\u003EExperience working with CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, etc.)\u003C/li\u003E\u003Cli\u003EHands-on experience using AI-driven security platforms to analyze vulnerabilities in code, dependencies, and cloud infrastructure\u003C/li\u003E\u003Cli\u003EGood understanding of OWASP MAS and common web and mobile vulnerabilities\u003C/li\u003E\u003Cli\u003EExperience building or improving risk management processes (risk assessment, SDLC integration, stakeholder visibility)\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ENice to have:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience building AppSec / DevSecOps practices from scratch\u003C/li\u003E\u003Cli\u003EExperience with threat modeling or architecture security reviews\u003C/li\u003E\u003Cli\u003EExperience working with cloud platforms (AWS, GCP)\u003C/li\u003E\u003Cli\u003EExperience with Kubernetes and container security\u003C/li\u003E\u003Cli\u003EParticipation in security incident response\u003C/li\u003E\u003Cli\u003ERelevant security certifications\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EYour journey: message from the recruiter \u0026gt; interview with manager \u0026gt; test\u0026gt; final interview \u0026gt; job offer.\u003C/p\u003E\u003Cp\u003EWhy appflame?\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EReal Impact: Implement your ideas on a global scale with millions of users.\u003C/li\u003E\u003Cli\u003ENo Barriers: Access to best practices from Snapchat, Meta, Google, and Apple.\u003C/li\u003E\u003Cli\u003EGrowth Environment: We provide all resources to implement cutting-edge AI and automation.\u003C/li\u003E\u003Cli\u003ECare: We don\u2019t leave our people alone with problems\u2014professional or personal.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EWe provide all conditions for your talents to be fully revealed. We are loyal to our people. Our loyalty doesn\u2019t fade at the end of the working day. We do not leave our people alone with their problems: neither professional nor personal.\u003C/p\u003E\u003Cp\u003EJoin us and flame up the world!\u003C/p\u003E\u003Cp\u003EWe are against all types of discrimination, bullying, and stereotypes. We provide equal employment opportunities regardless of race, skin color, religion, gender, sexual orientation, gender identity, age, marital status, health status or any other characteristics.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"security-engineer-at-af-85df09c5bf3a"},"url":"https://gurify.com/job/security-engineer-at-af-85df09c5bf3a","datePosted":"2026-05-01","validThrough":"2026-11-04T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Af","sameAs":"https://af.breezy.hr"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"UA"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Ukraine","item":"https://gurify.com/jobs/ukraine"},{"@type":"ListItem","position":3,"name":"Security Engineer","item":"https://gurify.com/job/security-engineer-at-af-85df09c5bf3a"}]}
```
