Personal information hidden
This job seeker has chosen to hide his personal information and contact info. You can contact him using this page: https://www.work.ua/resumes/20011228/
Application Security Engineer
- City of residence:
- Kyiv
- Ready to work:
- Kyiv, Remote
Contact information
Name, contacts and photo are only available to registered employers. To access the candidates' personal information, log in as an employer or sign up.
Uploaded file
This resume is posted as a file. The quick view option may be worse than the original resume.
Application Security Engineer · OWASP · Secure SDLC
[
PROFESSIONAL SUMMARY
Application Security engineer who came in through offensive security and governance and then learned to build. M.S. in Cybersecurity, web
and mobile penetration testing through EPAM's bootcamp (Metasploit, Nmap, OWASP-aligned reporting), and a year at KPMG assessing
bank applications against ISO 27001 and NIST. I implement security in the pipeline: supply-chain scanning with Trivy and tfsec, policy-as-
code with Kyverno, and keyless OIDC CI/CD on AWS EKS, all provisioned with Terraform. I work in Python, Bash, and Node.js / JavaScript
across web, mobile, and AWS microservices.
CORE COMPETENCIES
Application Security (AppSec) OWASP Top 10 Manual Penetration Testing Threat Modeling AWS Cloud Security (IaaS)
Node.js / TypeScript Python & Bash Security Frameworks (ISO 27001 / NIST)
WORK EXPERIENCE
Archilabs Sep 2024 - Feb 2025
Full Stack Developer · Houston, TX (Remote)
Engineered a web application converting AutoCAD drawings into real-time interactive 3D renders, applying secure coding practices across the
Node.js stack.
Optimized backend services for browser-based rendering, sustaining 200+ concurrent users with reduced latency.
Mission Zero May 2023 - Dec 2023
Full Stack Developer · Houston, TX
Designed scalable backend (Node.js) supporting 5,000 concurrent users and integrated REST APIs into a React Native mobile frontend across
15,000+ downloads.
Hardened data synchronization between mobile client and backend services, improving efficiency by 35%.
KPMG Dec 2021 - Dec 2022
Cybersecurity Consultant · Kyiv, Ukraine
Assessed bank applications and systems against ISO 27001 / 27002, NIST, and VAIT across a 5-client portfolio; identified and reported
vulnerabilities; lifted compliance ~40%.
Provided technical guidance to developers, translating audit findings into remediation that engineering teams adopted into delivery and
change-management processes.
PROJECTS
Web Penetration Testing Bootcamp - EPAM Manual Pentest & OWASP
Intensive hands-on web and mobile penetration testing with Metasploit and Nmap: vulnerability identification, threat modeling, and OWASP-
aligned remediation reporting across web applications and mobile clients.
Tech: OWASP Top 10, Metasploit, Nmap, threat modeling, manual vulnerability assessment
Project-Ramus - Application Security & AWS IaaS Hardening AppSec + Cloud github.com/grepxz/Project-Ramus
Built a security-first delivery platform on AWS EKS (Kubernetes v1.30): supply-chain scanning with Trivy and tfsec, policy-as-code with
Kyverno, keyless GitHub Actions CI/CD via AWS OIDC (no long-lived credentials), and secrets managed by the External Secrets Operator backed
by AWS Secrets Manager. Terraform-provisioned end to end.
Tech: AWS (EKS, IAM, Secrets Manager, OIDC), Trivy, tfsec, Kyverno, Terraform, ArgoCD, GitHub Actions
Project-Gemma - Automated CI/CD on AWS CI/CD github.com/grepxz/Project-Gemma
Hands-free Jenkins + Docker pipeline that deploys a Flask + MySQL application to AWS EC2 on every push.
Tech: Jenkins, Docker, Docker Compose, AWS EC2, MySQL, Linux
EDUCATION
M.S., Cybersecurity - Kyiv National University of Construction and Architecture Jan 2023
SKILLS
Application Security: OWASP Top 10, manual penetration testing (Metasploit, Nmap), threat modeling, vulnerability identification, secure code
review, secure SDLC
Cloud & IaaS Security: AWS (EC2, EKS, IAM, Secrets Manager, OIDC, CloudTrail concepts), Kubernetes security, Terraform, policy-as-code
(Kyverno), supply-chain scanning (Trivy, tfsec)
Security Frameworks: ISO 27001 / 27002, NIST, VAIT, GDPR awareness, cryptography, authentication / authorization, incident response
Programming: Python, Bash, JavaScript / Node.js, TypeScript (working knowledge), SQL (MySQL)
Web & Mobile: REST APIs, React / React Native, microservices, TLS / HTTPS / DNS
AI Tooling: Claude, Cursor, Copilot for code review, security policy drafting, and documentation
Languages: Ukrainian (native), English (fluent), Russian (fluent), Spanish (A1)
More resumes of this candidate
Considering positions: IT Support Specialist (Service Desk), Системний адміністратор, Інженер з ІТ-інфраструктури
Kyiv, Remote
Hanna Nyzhnia | | | nyzhnia.com | Barcelona, Spain PROFESSIONAL SUMMARY Service-oriented IT Support professional certified in CompTIA A+, Network+, and the Google IT Support Professional Certificate...
Kyiv, Remote
Hanna Nyzhnia | | | nyzhnia.com | Barcelona, Spain PROFESSIONAL SUMMARY Junior cloud engineer with an M.S. in Cybersecurity and a strong Linux and networking foundation - TCP/IP, routing, firewalls...
Considering positions: DevOps engineer, Network engineer, Information security engineer, 1 more position
Kyiv, Remote
Higher education · Full-time
- Full Stack Developer, Archilabs, 6 months
- Full Stack Developer, Mission Zero, 8 months
Similar candidates
-
Інженер-конструктор
Kharkiv, Remote -
Інженер БпЛА
50000 UAH, Kyiv -
Інженер з прототипування БПЛА
Kyiv -
Field Engineer
Kyiv -
Інженер-проєктувальник
20000 UAH, Kyiv