Enable job alerts via email!

Application Security Engineer (Visa Sponsorship and relocation to the UK offered)

MoonPay

London

Remote

GBP 60,000 - 100,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a forward-thinking company as an Application Security Engineer, where you'll play a vital role in safeguarding digital assets in the Web3 space. This innovative firm is dedicated to fortifying its systems through rigorous security practices, including penetration testing and threat modelling. You'll collaborate with development teams to integrate security best practices throughout the software development lifecycle. With a commitment to continuous improvement, you'll engage with the wider security community while enjoying perks like unlimited holidays and a supportive work environment. If you're passionate about security and eager to make an impact, this is the opportunity for you.

Benefits

Equity package
Unlimited holidays
Paid parental leave
Annual training budget
Home office setup allowance
Monthly budget for products
Freedom and autonomy
Working in a fast-growing industry

Qualifications

  • Experience in application, infrastructure, cloud, and mobile security.
  • Hands-on experience with penetration testing methodologies and tools.
  • Understanding of Threat Modelling principles.

Responsibilities

  • Conduct threat modelling and provide actionable recommendations.
  • Support penetration testing and vulnerability assessments.
  • Manage Bug Bounty program reports and incident response.

Skills

Threat Modelling
Penetration Testing
Application Security
Infrastructure Security
Cloud Security
Mobile Security
JavaScript
TypeScript
Cryptography

Education

Relevant Security Certifications (CISSP, OSCP, CEH)

Tools

Cloudflare WAF

Job description

Application Security Engineer (Visa Sponsorship and relocation to the UK offered)

2 days ago Be among the first 25 applicants

Get AI-powered advice on this job and more exclusive features.

About MoonPay Hi, we’re MoonPay. We’re here to onboard the world to Web3.

Why? Because we think Web3 is a unique and democratising technology. It gives people back control of their money, digital identity, data, and property like nothing else before it.

What We Do We’re the leading infrastructure company in Web3. This means we offer our partners everything from payment solutions (we call them 'Ramps') to minting software for digital collectibles, like NFTs. And over 30 million people around the world now trust our products — just take a look on Trustpilot.

We’re also big on collaborations. And we've worked on stunts, drops, and partnerships with some of the world's most prestigious and forward-thinking brands.

But that’s not all. We have also built our own consumer app because we wanted to see if we could build a better Web3 account. It’s taken off in a big way, and we're working hard to continually improve it and to strive for perfection.

So whatever your background, we’re sure there’s something for you here. Come help us build the future of Web3 and digital ownership.

Location supported

This role can be performed remotely from the United Kingdom, Poland, South Africa, Spain, Portugal, or Romania. If you are currently located outside these countries, relocation will be required. Visa sponsorship and relocation support are available for the UK only for this role.

Unfortunately we do not offer business to business contracting arrangements.

About the Opportunity

Our Product Security team is a dynamic blend of proactive defenders and inquisitive problem-solvers. We're dedicated to fortifying our systems through rigorous security reviews and hands-on penetration testing. We actively manage our Bug Bounty program, ensuring swift response and remediation. We leverage cutting-edge tools like Cloudflare's WAF to build robust defenses. Collaboration is key, as we embed security best practices throughout the SDLC. We are constantly researching emerging threats, crafting effective mitigation strategies, and empowering our engineering teams with comprehensive training. We maintain up-to-date security standards and lead incident response with precision. We are passionate about fostering a secure environment and contributing to the wider security community.

What you will do

  1. Conduct thorough threat modelling of Technical Design Documents (TDD) practices and provide actionable recommendations for improvement
  2. Contribute to and support penetration testing activities, including vulnerability assessments and PoC development
  3. Triage, respond and investigate Bug Bounty program reports
  4. Implement and manage Web Application Firewalls (WAFs) and other security tools, preferably with experience in Cloudflare
  5. Collaborate with development teams to integrate security best practices throughout the software development lifecycle (SDLC)
  6. Research and evaluate emerging security threats and vulnerabilities, and develop mitigation strategies
  7. Develop and deliver security training and awareness programs to engineering teams
  8. Contribute to the development and maintenance of security standards and keep documentation up to date
  9. Lead and participate in incident response activities, including investigation and remediation

About You

  • You have developed a breadth of experience across multiple security domains, including application security, infrastructure security, cloud security, and mobile security, with a proven ability to connect and integrate these areas for a holistic security approach
  • You have a strong understanding of Threat Modelling principles and their application to secure software development
  • You have hands-on experience with penetration testing methodologies and tools
  • You have previous experience with WAF configuration and management, ideally including Cloudflare
  • You have performed mobile penetration testing and acquired techniques and tools
  • You are proficient in Javascript and Typescript programming languages
  • You are comfortable explaining technical concepts like vulnerabilities and discussing effective mitigations
  • You are self-motivated, can work effectively in a remote setting while maintaining a team-focused mindset
  • Your background includes working in disruptive technologies, successfully launching products, ideally within FinTech, SaaS, Crypto
  • If you hold relevant security certifications (e.g., CISSP, OSCP, CEH), they are a plus but not required
  • You have a good understanding of cryptography and its applications
  • You contribute to the security community through open source, participating in CTFs, or giving talks at security conferences

What you will be working with/on

As part of our Product Security team, you'll be instrumental in safeguarding our digital assets. You'll conduct in-depth security reviews of technical designs, ensuring robust defenses from the outset. You'll actively participate in penetration testing, identifying and mitigating vulnerabilities. You'll triage and respond to Bug Bounty reports, maintaining a proactive security posture. You'll configure and manage our Web Application Firewalls, particularly Cloudflare, to thwart attacks. You'll collaborate closely with development teams, integrating security seamlessly into the SDLC. You'll research emerging threats, developing strategies to stay ahead of adversaries. You'll contribute to and deliver security training, fostering a security-conscious culture. You'll help maintain and improve our security standards and documentation. You'll participate in incident response, ensuring swift and effective remediation. You'll also have opportunities to engage with the wider security community.

Most importantly, though, you will embody the core principles that everyone here at MoonPay lives by. Our “BLOCK Values” are at the heart of everything we do - and they are…

  • B - Be Hungry
  • L - Level Up
  • O - Own It
  • C - Crypto Curious
  • K - Kaizen

MoonPay Perks

  • Equity package
  • Unlimited holidays
  • Paid parental leave
  • Annual training budget
  • Home office setup allowance
  • Monthly budget to spend on our products
  • Working in a disruptive and fast-growing industry where the possibilities are endless
  • Freedom, autonomy and responsibility

Research shows women are less likely than men to apply if they do not meet 100% of the skills listed. We encourage you to apply even if you meet approximately 75% of the requirements. Skills can be learned, diversity cannot.

Please let us know if you require accommodations for the interview process.

Commitment To Diversity

At MoonPay, we believe every voice matters. We strive for a respectful environment free of discrimination. We are an equal opportunity employer and prohibit discrimination based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or protected veteran status. We also provide reasonable accommodations for applicants with disabilities.

Please be aware that MoonPay does not conduct AI-led interviews without a MoonPay representative on video call and will never ask for personal documents or money during the interview process. Beware of fraudulent emails claiming to be from MoonPay.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Cloud Security Engineer

TrueLayer

Greater London

Remote

GBP 50,000 - 90,000

9 days ago