What You Will Do
- performs web, mobile application, and internal penetration tests, source code reviews, threat analysis, social-engineering assessments,
- supports blue teams when needed,
- researches new attack vectors and stays current with cybersecurity news and trends,
- trains Quality Assurance and Development teams in standard security testing techniques and secure software development.
What You Will Need
- have 4+ years of working experience in web application security,
- have hands-on experience in security testing of web applications, web services, mobile applications, APIs, etc.,
- have experience securing REST APIs and web services,
- have experience using and implementing SAST / DAST tools such as Fortify, Veracode, Checkmarx, or other similar tools,
- know how to conduct penetration tests of information systems using commercial and open-source exploitation tools,
- have a good understanding of standard security vulnerabilities and common remediation as published by OWASP, SANS, etc.,
- have experience working with secure coding methodology and best practices and their implementation within engineering teams,
- will support developers of our business units in their SDLC and provide guidance regarding mitigations to emerging threats,
- will review application source code based on static application security testing tools,
- will be engaging in security research to remain current on vulnerabilities and testing tools,
- will be creating detailed, professional documentation/reports that clearly communicate vulnerabilities, mitigation strategies, and remediation steps,
- have the ability to work on multiple projects concurrently and be committed to providing exemplary customer service,
- have strong written and verbal communication skills in English,
- have Python, JavaScript, PHP programming experience as a plus,
- have knowledge in scripting (any language) and experience in automation scripts for application security testing as a plus,
- have familiarity with cloud security, particularly AWS security concepts, as a plus,
- have certifications such as eWAPTx, OSCP, OSWE, etc., as a plus,
- are able to work in a team-centric environment,
- have strong critical thinking and analytical skills,
- have experience in executing white, gray, or black box security posture assessments and completing detailed reports that outline the findings and recommendations.
What We Offer
- Enjoy a monthly meal allowance designed to enhance your daily routine.
- Access comprehensive private health insurance.
- Feed your curiosity with access to Spotify, LinkedIn Learning, Blinkist, MasterClass, Neoskola, and CloudGuru.
- Level up with internal trainings covering AI fundamentals, coding, foreign languages, and a wide range of personal development skills.
- Be part of a diverse team that’s as global as it gets, where every voice is heard and 50+ nationalities build together.
- Become a Shareowner through our eligibility-based “ESOP” and own a piece of what you build.
- Help build the team you want to work with and enjoy rewarding referral bonuses.
- Opportunities to give back to your community through volunteering and purpose-driven social impact projects.
- From global retreats to team-building activities, expect year-round events that turn into lifelong memories.
- Get inspired by the greatest minds in the tech industry through events like our Tech & Dev Talks.
- Work from anywhere in Turkey through our fully remote setup.
Skills Required
- 4+ years of professional experience in web application security
- Hands-on security testing experience with web applications, web services, mobile applications, and APIs
- Experience securing REST APIs and web services
- Experience using or implementing SAST/DAST tools
- Knowledge of penetration testing information systems using commercial and open-source exploitation tools
- Understanding of common security vulnerabilities and remediation practices from OWASP, SANS, or similar standards
- Experience with secure coding methodologies and implementation within engineering teams
- Ability to support developers during the SDLC and advise on emerging-threat mitigations
- Experience reviewing application source code using static application security testing tools
- Experience conducting security research on vulnerabilities and testing tools
- Ability to create detailed security reports covering vulnerabilities, mitigations, and remediation steps
- Ability to manage multiple projects concurrently
- Strong written and verbal communication skills in English
- Ability to work in a team-centric environment
- Strong critical-thinking and analytical skills
- Experience executing white-box, gray-box, or black-box security posture assessments
- Programming experience with Python, JavaScript, or PHP
- Scripting and automation experience for application security testing
- Familiarity with cloud security, especially AWS security concepts
- Certifications such as eWAPTx, OSCP, or OSWE
Insider One Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Insider One and has not been reviewed or approved by Insider One.
-
Fair & Transparent Compensation — Pay sentiment trends generally positive overall, with pay described as competitive in some roles and markets. Recent role-specific ranges and compensation benchmarks suggest market-aligned pay bands in several functions.
-
Strong & Reliable Incentives — Bonus structures and performance-linked earnings potential appear to meaningfully increase total compensation, particularly in commercial roles. Variable pay and commission mechanics are portrayed as providing upside when targets are achieved.
-
Leave & Time Off Breadth — Time-off policies are described as generous, including an unlimited PTO approach and in some cases additional holiday time. Flexible working hours also contribute to perceived time-off and flexibility value.
Insider One Insights
What We Do
Insider One is the #1 platform that brings everything marketing and customer engagement teams need in one place so they can reach their peak potential and become unstoppable. With AI at its core and an integrated Customer Data Platform (CDP), Insider One unites data, personalization, and journey orchestration across the most extensive set of natively supported channels, including WhatsApp, SMS, Email, Web, App, and Site Search. Insider One provides the ultimate vendor experience, proven in fifteen industries and more than 30 countries for more than a decade, to help teams be first, be focused, and be progressive, redefining what it means to lead in customer engagement. Trusted by 2,000+ customers, including some of the world’s most loved brands like Samsung, L’Oréal, Unilever, Allianz, ING Group, Toyota, Singapore Airlines, and GAP, to accelerate growth, build customer love, and become a market leader. Loved by customers, recognized by analysts, Insider One is the only vendor recognized as the #1 leader in all the capabilities marketing and customer engagement teams need, including AI, Customer Data Management, Cross-Channel Journey Orchestration, and Personalization, offering brands unrivaled product excellence within a single consolidated platform. Accolades include: - Leader in the IDC MarketScape: Worldwide AI-Enabled Marketing Platforms for Enterprise Companies 2025 - Leader in the Gartner Magic Quadrant for Personalization Engines, 2025 - #1 Customer Choice: 2025 Gartner Voice of the Customer for Personalization Engines - Leader in the Forrester Wave for Experience Optimization Platforms, Q4 2024 - The Gartner Customers’ Choice for Multichannel Marketing Hubs in 2025 - The #1 G2 Leader in 11 categories, including CDP, Personalization Engines, Mobile Marketing, Customer Journey Analytics, SMS Marketing, WhatsApp Marketing, eCommerce Search, and eCommerce Personalization, with a perfect 100/100 user satisfaction score.







