application security engineer in fintech

HireHi

United States

A distancia

USD 110.000 - 150.000

Jornada completa

hace 38 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

No envíes un currículum genérico — crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Гибкий график работы
Поддержка благополучия (Wellbeing)
Возможности карьерного роста
Работа в стартапоподобной глобальной团队

Descripción de la vacante

Altery ищет инженера по безопасности приложений для полного цикла обработки уязвимостей и внедрения практик Secure SDLC. Ваша роль включает анализ архитектур, динамическое тестирование и взаимодействие с командами разработки для устранения критических рисков.

Требуется опыт в SAST/DAST/SCA, NFC, а также работа с threat modelling. Гибкий график, работа в глобальной команде и возможности роста в стартапообразной среде — приветствуются.

Formación

  • 2+ года опыта как инженер по безопасности приложений
  • Глубокое понимание современной веб- и мобильной архитектуры (микросервисы, контейнеры, CI/CD, Secure SDLC)
  • Навык внедрения SAST/DAST/SCA, детекции секретов, сканирования образов контейнеров и контроля безопасности в CI/CD
  • Опыт triage результатов сканирования и Bug Bounty, включая верификацию и PoC
  • Навыки тестирования безопасности веб/API за пределами OWASP Top 10: CSP, заголовки безопасности, cookies, бизнес-логика
  • Опыт тестирования мобильной безопасности по OWASP MASVS/MASTG, включая root/эмулятор, SSL pinning, anti-tampering
  • Опыт threat modelling и security reviews архитектурных решений
  • Практические знания безопасности цепочки поставок ПО и управления секретами
  • Свободное владение английским языком в чтении/письме
  • Способность доводить найденное до решения, работать с инженерами, любознательность к обучению, AI и автоматизации

Responsabilidades

  • Владеть на всём цикле обработки уязвимостей: трия сканеров и Bug Bounty; верифицировать, оценивать Exploitability и создавать PoC
  • Объяснять уязвимости командам разработки и помогать исправлять корневые причины
  • Разрабатывать и улучшать Secure SDLC, внедряя проверки и gates в CI/CD
  • Рассматривать архитектуры через threat modelling и формулировать требования к безопасности
  • Динамически тестировать веб, API и мобильные приложения, фокусируясь на бизнес-логике
  • Укреплять безопасность цепочки поставок ПО и управление секретами
  • Ежемесячно отчитываться по состоянию безопасности приложения

Conocimientos

Application Security
Web & Mobile Security
Threat Modelling
CI/CD Integration
Bug Bounty Triage
Root Cause Analysis
Automation Curiosity

Herramientas

SAST tools
DAST tools
SCA tools
Secret detection
Container image scanning
CI/CD security gates

Descripción del empleo

Описание:

Altery builds products that help businesses and people move money across borders, currencies and digital assets with less friction.

Задачи:
  • Own security findings end to end: triage scanner and Bug Bounty results, validate them manually, assess exploitability, and build proofs of concept
  • Explain vulnerabilities to development teams and help them fix root causes
  • Build and improve the Secure SDLC by embedding security checks and gates into CI/CD pipelines
  • Review application architectures and new features through threat modelling and define clear security requirements
  • Dynamically test web, API, and mobile applications, focusing on business logic flaws scanners may miss
  • Strengthen software supply chain security and secrets management, including dependency control, secrets detection, and rotation
  • Report monthly on the application security posture and areas for improvement
Требования:
  • 2+ Years as an Application Security Engineer
  • Strong understanding of modern web and mobile architecture, including microservices, containers, CI/CD, and Secure SDLC principles
  • Hands-on experience integrating SAST, DAST, SCA, secret detection, container image scanning, and security gates into CI/CD pipelines
  • Experience triaging scanner and Bug Bounty findings, including manual validation, exploitability assessment, PoCs, and communicating fixes to developers.
  • Solid web and API security testing skills beyond the OWASP Top 10, including CSP, security headers, cookies, and business logic flaws; confidence with common proxy and testing tools
  • Mobile application security testing experience based on OWASP MASVS/MASTG, including root and emulator detection, SSL pinning, and anti-tampering
  • Experience with threat modelling and security reviews of architecture decisions and new features.
  • Practical knowledge of software supply chain security and secrets management
  • Fluent English for technical reading, writing, and communication.
  • Takes ownership of findings through to resolution, collaborates with engineers, and is curious about learning, experimentation, AI, and automation.
Будет плюсом:
  • fintech or payments experience, including PSD2/SCA, cardholder data, PIN protection, and PCI DSS awareness
  • running or supporting a Bug Bounty programme or participating as a researcher
  • using AI and LLM tools in AppSec and understanding AI integration risks
  • cloud security basics, ideally AWS
  • ELK, security dashboards and metrics, and detecting sensitive data in logs
  • Security Champions programmes, secure coding checklists, or developer training
  • scripting for automation and data analysis
  • TCP/IP and core network and web protocols
Условия:
  • Competitive compensation that rewards your contribution
  • Flexible working hours aligned with local hours, with core hours from 9am–2pm UK time
  • Occasional visits to a nearby hub are welcomed
  • Wellbeing support, including additional sick leave
  • Career growth opportunities through ownership, skill development, and impact
  • Startup environment with a global team across countries, cultures, and time zones
Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

security engineer for HR technology
security engineer for HR technology

HireHi • EE. UU.

A distancia
USD 150.000 - 210.000
Annual training budget
Pension plan
Travel reimbursement
+3
security engineer in fintech
security engineer in fintech

HireHi • EE. UU.

A distancia
USD 120.000 - 210.000
Relocation to Cyprus
Learning and development budget
Fully paid vacation and sick leave
+1
penetration tester in iGaming
penetration tester in iGaming

HireHi • EE. UU.

A distancia
USD 110.000 - 180.000
Оплачиваемый отпуск
Больничные
Возможность профессионального роста
+1
qa engineer (auto) in fintech
qa engineer (auto) in fintech

HireHi • EE. UU.

Presencial
USD 47.000 - 68.000
Competitive salary
Career growth opportunities
International work environment
+5
penetration tester in cybersecurity
penetration tester in cybersecurity

HireHi • EE. UU.

A distancia
USD 120.000 - 160.000
Private health insurance
Performance-based bonus
Professional training portal access
+2
Application Security Engineer
Application Security Engineer

Softswiss • Town of Poland (NY)

Presencial
USD 120.000 - 150.000
Private health insurance
Sports benefits
Free English lessons (online)
+3
agentic product engineer for fintech
agentic product engineer for fintech

HireHi • EE. UU.

Híbrido
USD 120.000 - 180.000
Local insurance coverage
Flexible working arrangements
Application Security Engineer (X Money)
Application Security Engineer (X Money)

xAI • Washington

Presencial
USD 120.000 - 160.000
Health insurance
Vision & dental benefits
Visa sponsorship
Product Security Engineer
Product Security Engineer

GoMining • Georgia

Presencial
USD 120.000 - 180.000
Professional growth
Remote or hybrid format
Vacation and holidays
+3
AppSec Engineer - Secure SDLC & Bug Bounty
AppSec Engineer - Secure SDLC & Bug Bounty

HireHi • EE. UU.

A distancia
USD 110.000 - 150.000
Гибкий график работы
Поддержка благополучия (Wellbeing)
Возможности карьерного роста
+1