Application Security Engineer

Pepperstone

Hungary (CT)

Hybrid

USD 120,000 - 160,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive salary
Company bonus scheme
Collaborative and friendly culture
Hybrid working
Remote work up to 4 weeks/year

Job summary

Pepperstone is seeking an experienced Application Security Engineer to embed security across the software development lifecycle. You will partner with engineering and product teams to identify, assess, and remediate vulnerabilities in applications and APIs, driving secure coding practices and security-aware culture.

You will lead security assessments, integrate controls into CI/CD pipelines, and mentor engineers while coordinating bug bounty programs.

Qualifications

  • 8+ years of information security experience with 3+ years in application/software security engineering.
  • Solid understanding of OWASP Top 10, business logic flaws and API security risks.
  • Hands-on with security testing tools (Burp Suite, OWASP ZAP, Semgrep, Checkmarx, Snyk).
  • Proficiency in at least one language (Python/JavaScript/Java/Go) for code review/automation.
  • Experience integrating security tooling into CI/CD (GitHub Actions/Jenkins/GitLab CI).
  • Familiarity with AWS/Azure/GCP cloud security principles for app hosting/deployment.
  • Fluency in English; Hungarian a plus.
  • Certifications such as OSCP, GWEB, CEH are advantageous.

Responsibilities

  • Perform application security assessments across web, mobile, and API surfaces.
  • Integrate security controls into CI/CD pipelines using SAST/DAST/SCAs and secrets tooling.
  • Identify, triage, and remediate vulnerabilities with engineering teams.
  • Define and maintain application security standards and developer-facing docs.
  • Champion secure-by-design principles during design/architecture phases.
  • Lead bug bounty and responsible disclosure programmes and triage issues.
  • Conduct security training and awareness sessions for engineers.
  • Evaluate third-party libraries and vendor integrations for security risk.
  • Collaborate with Security team on incident response for app-layer vulnerabilities.

Skills

Information security
Application security
Communication skills
English fluency

Tools

Burp Suite
OWASP ZAP
Semgrep
Checkmarx
Snyk

Job description

The Pepperstone story started in 2010. We know what it's like to trade the world's markets. Our team describes us as a place for the curious and the driven, and we like to do things a little differently; as a transformative global fintech we're digital, nimble, connected, and united in our vision to create a better way to trade.

We thrive on progress - for our clients and for ourselves. Our organisational culture is ever-evolving, vibrant, diverse, global and results focused. You'll find our 700+ team across 12 regions and 9 time zones.

The Role

The Application Security Engineer exists to embed security throughout the software development lifecycle at Pepperstone. You will partner with engineering and product teams to identify, assess, and remediate security vulnerabilities in our applications and APIs, ensuring that security is a first‑class citizen in every release. You will drive adoption of secure coding practices, conduct application security assessments, and help build a security‑aware engineering culture across the organisation. This position reports to the Head of Product Security, Limassol, Cyprus.

What You'll Be Doing
  • Perform application security assessments including threat modelling, secure code reviews, and penetration testing across web, mobile, and API surfaces.
  • Partner with development teams to integrate security controls into CI/CD pipelines using SAST, DAST, SCA, and secrets detection tooling.
  • Identify, triage, and track vulnerabilities through to remediation, working closely with engineering teams to provide actionable guidance.
  • Define and maintain application security standards, secure coding guidelines, and developer‑facing security documentation.
  • Champion security‑by‑design principles and provide hands‑on guidance during the design and architecture phases of new features and products.
  • Lead and support bug bounty and responsible disclosure programmes, coordinating triage and remediation of externally reported issues.
  • Conduct security training and awareness sessions for software engineers, embedding secure development practices across teams.
  • Evaluate third‑party libraries, open‑source components, and vendor integrations for security risk.
  • Collaborate with the broader Security team on incident response activities related to application‑layer vulnerabilities.
About You
  • 8+ years of experience in information security, with at least 3 years specializing in application security or software security engineering.
  • Solid understanding of common vulnerability classes including OWASP Top 10, business logic flaws, and API security risks.
  • Hands‑on experience with security testing tools such as Burp Suite, OWASP ZAP, Semgrep, Checkmarx, Snyk, or equivalent.
  • Proficiency in at least one programming or scripting language (Python, JavaScript, Java, Go, or similar) to support code review and automation.
  • Experience integrating security tooling into CI/CD pipelines (GitHub Actions, Jenkins, GitLab CI, or similar).
  • Familiarity with cloud security principles across AWS, Azure, or GCP, particularly as they relate to application hosting and deployment.
  • Strong communication skills with the ability to articulate security risk to both technical and non‑technical stakeholders.
  • Relevant certifications such as OSCP, GWEB, CEH, or equivalent are advantageous.
  • Experience in a regulated financial services or fintech environment is a plus.
  • Fluency in English; Hungarian language skills are an advantage.
  • Ability to live the Pepperstone values.
  • Committed to ongoing learning and development.
Why you will enjoy working with us
  • Competitive salary structure including company bonus scheme
  • Genuinely collaborative and friendly culture
  • Flexible and hybrid working
  • Remote working option – work from anywhere for up to 4 weeks per year
  • Ongoing personal development & learning opportunities
  • 3 paid volunteering days per year & Workplace Giving Program
  • Periodic recognition and reward programs for outstanding performance and achievements
  • Frequent events and celebrations
  • Employee Assistance Program & Wellbeing Initiatives
  • Convenient and cozy office located near Astoria at KLUSTER Coworking
More about Pepperstone

We're a regulated online Forex and CFD trading platform. With the scale of a global fintech and the agility of a start‑up, we arm our clients with everything they need to take on the global markets with confidence. You will be part of a wider passionate and friendly team, and whilst things may not always go to plan, we learn quickly and move forward with impact.

Equal Opportunity & Inclusion

Pepperstone is an equal‑opportunity employer. We are passionate about building a diverse workplace and strongly encourage applications from any background. We are a 2025 Circle Back Initiative Employer – we respond to every applicant. We respect our team members' experiences and will never pay to remove a negative review.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

GoMining • Town of Poland (NY)

Hybrid
USD 120,000 - 190,000
Professional growth support
Flexible hours
Vacation and holidays
Product Security Engineer
Product Security Engineer

GoMining • Georgia

Hybrid
USD 120,000 - 180,000
Professional growth
Remote or hybrid format
Vacation and holidays
+3
Application Security Engineer
Application Security Engineer

Softswiss • Town of Poland (NY)

On-site
USD 120,000 - 150,000
Private health insurance
Sports benefits
Free English lessons (online)
+3
Application Security Manager
Application Security Manager

Alter Domus • Chicago (IL)

Hybrid
USD 120,000 - 150,000
Flexible arrangements
Generous holidays
Employee Share Plan
Senior Product Security Engineer
Senior Product Security Engineer

Airwallex • United States

On-site
USD 100,000 - 130,000
Vice President, Application Security Specialist
Vice President, Application Security Specialist

CLS-Group • Iselin (PA)

Hybrid
USD 140,000 - 180,000
Hybrid work model
Private medical insurance
401(k) match
+1
Staff Software Engineer, Security Platform
Staff Software Engineer, Security Platform

United States Digital Space LLC • United States

Hybrid
USD 84,000 - 114,000
Internship Programme 2027: Information Security Engineer (Appsec)
Internship Programme 2027: Information Security Engineer (Appsec)

Revolut • Town of Poland (NY)

Hybrid
Visa assistance
Travel costs coverage
Accommodation support
Graduate Programme 2027: Information Security Engineer (Appsec)
Graduate Programme 2027: Information Security Engineer (Appsec)

Revolut • Town of Poland (NY)

Hybrid
USD 60,000 - 85,000
Staff Product Security Engineer
Staff Product Security Engineer

Airwallex Pty Ltd. • San Francisco (CA)

On-site
USD 130,000 - 170,000