Senior Application Security Engineer

Socket.dev

Belgrade (MT)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Unlimit, a global fintech ecosystem, seeks a Senior Application Security Engineer to harden applications, APIs, and CI/CD processes. You’ll automate testing, model threats, and integrate security into development across teams.

You’ll lead secure design reviews, code analysis, and vulnerability remediation, while advancing ASMP and AI‑assisted security workflows in a fast‑growing, AI‑driven infrastructure.

Qualifications

  • 5+ years in Application Security, Software Security, DevSecOps, or Software Engineering with a security focus.
  • Experience in fintech or crypto is a plus; strong software development background.
  • Threat modelling, secure design reviews, and manual code reviews experience.
  • Secure SDLC, CI/CD security, and automated security testing in pipelines.

Responsibilities

  • Drive secure software development practices across the organisation.
  • Perform application security assessments, design reviews, and threat modelling.
  • Conduct manual source code reviews for critical apps and remediation.
  • Integrate security testing (SAST/DAST/SCA/API) into SDLC and IaC security.
  • Build automated security workflows in GitLab CI/CD and ASPM capabilities.
  • Collaborate with engineering to remediate vulnerabilities and improve resilience.
  • Coordinate external assessments and drive remediation from findings.
  • Develop AI-powered security workflows, reviews, and code analysis patterns.

Skills

DevSecOps
Threat modelling
Secure SDLC
CI/CD security
SAST
DAST
SCA
API security
GitLab workflows
Automation
AI-assisted security
Java
Go
Python
Node.js
PHP
Dart (Flutter)

Tools

GitLab CI/CD

Job description

About Unlimit

Unlimit is a global fintech ecosystem built to eliminate financial borders holding businesses back. The company provides the extensive infrastructure needed to scale globally, integrating payment processing, multi-currency business accounts, BaaS and crypto gateways into a single, intelligent platform.

Across 17 offices globally, Unlimit bridges hyper‑local expertise with a high‑capacity financial network, giving companies the agility to expand across regions with operational confidence and speed. Driving the evolution of payments, Unlimit is transforming its infrastructure from human‑operated fintech into AI‑native financial infrastructure — where APIs are consumed by machines, integrations are negotiated by agents, and systems evolve continuously through intelligent automation. Our next users are not only humans. They are AI agents acting on behalf of humans and businesses.

Unlimit serves more than the needs of businesses today; we are building the nervous system for a borderless global economy.

Your Challenge

As a Senior Application Security Engineer, you’ll be a hands‑on technical expert responsible for improving the security of Unlimit’s applications, APIs, and development processes. You’ll help engineering teams identify and remediate security risks early, automate security testing, and integrate security seamlessly into modern CI/CD pipelines.

This role is ideal for someone who combines strong software engineering fundamentals with practical offensive security knowledge and enjoys building scalable, developer‑friendly security solutions through automation and AI.

What You’ll Do
  • Drive secure software development practices across the organisation.
  • Perform application security assessments, secure design reviews, and threat modelling for new and existing products.
  • Conduct manual source code reviews for business‑critical applications and support remediation of complex security issues.
  • Integrate and optimise security testing throughout the SDLC, including SAST, DAST, Software Composition Analysis (SCA), API security testing, and Infrastructure as Code (IaC) security.
  • Build and improve automated application security workflows within GitLab CI/CD pipelines.
  • Own and continuously improve Application Security Posture Management (ASPM) capabilities.
  • Partner closely with software engineering teams to identify vulnerabilities early and implement practical, scalable security controls.
  • Support penetration testing activities by coordinating external assessments, validating findings, and driving remediation.
  • Contribute to the development of internal AI‑powered and agentic application security workflows, including automated security reviews, code analysis, and vulnerability triage.
  • Research emerging attack techniques and translate them into practical improvements across secure development and security testing.
  • Develop security guidance, reusable patterns, and engineering standards that enable developers to build secure software at scale.
What We’re Looking For
  • 5+ years of experience in Application Security, Software Security, DevSecOps, or Software Engineering with a strong security focus.
  • Previous experience in fintech is preferred; experience in cryptocurrency is a strong plus.
  • Strong software development background with hands‑on experience across modern application architectures.
  • Experience performing threat modelling, secure design reviews, and manual code reviews.
  • Strong understanding of Secure SDLC principles and practical application security engineering.
  • Experience implementing and maintaining automated security testing within CI/CD pipelines.
  • Hands‑on experience with SAST, DAST, SCA, API security testing, ASPM, and modern application security tooling.
  • Practical understanding of modern attack techniques, exploitation methods, and secure coding practices.
  • Experience collaborating directly with engineering teams to remediate vulnerabilities and improve application resilience.
  • Strong scripting or programming skills in one or more of the following: Java, Go, Python, Node.js, PHP, or Dart (Flutter).
  • Experience working with GitLab‑based development workflows.
  • A pragmatic, engineering‑first mindset with a passion for automation and AI‑assisted security.
Nice to Have
  • Practical penetration testing experience or an offensive security background.
  • Bug bounty participation or responsible vulnerability disclosure experience.
  • OSCP, OSWE, or similar offensive security certifications.
  • Experience with application or software architecture, including secure architecture design and security patterns.
  • Experience developing AI‑powered or agentic security automation.
  • Contributions to open‑source security projects, security research, or technical community initiatives.

Unlimit is an equal opportunity employer.

We believe passionately that employing a diverse workforce is central to our success.

We make recruiting decisions based on your experience and skills.

We welcome applications from all members of society irrespective of age, sex, disability, sexual orientation, race, religion or belief.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of Cyber Security
Head of Cyber Security

Socket.dev • Belgrade (MT)

Hybrid
USD 138,000 - 208,000
Relocation to Belgrade
Competitive compensation
Annual performance bonus
+1
Head of Information Security
Head of Information Security

Unlimit • United States

On-site
USD 180,000 - 320,000
Relocation to Belgrade, Serbia
Annual performance bonus
Comprehensive benefits package
Senior Application Security Engineer: AI‑Driven Security & CI/CD
Senior Application Security Engineer: AI‑Driven Security & CI/CD

Socket.dev • Belgrade (MT)

On-site
USD 120,000 - 180,000
Staff Application Security Engineer
Staff Application Security Engineer

Triwill Group • United States

On-site
USD 120,000 - 145,000
Fully remote work arrangement
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital | CubiCasa • Reno (NV)

On-site
USD 111,000 - 144,400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Senior Application Security Engineer
Senior Application Security Engineer

AgileEngine • United States

Hybrid
USD 120,000 - 180,000
Flextime
Professional growth
Competitive compensation
+2
Sr. Manager, Application Security
Sr. Manager, Application Security

Prosper Marketplace • United States

Hybrid
USD 226,000 - 270,000
401(k) with 5% company match
Flexible time off
Paid parental leave
+1
Staff Application Security Engineer
Staff Application Security Engineer

Nclusion, Inc. • Palo Alto (CA)

On-site
USD 180,000 - 240,000
401k with match
Medical Insurance
Dental Insurance
+4
Staff Application Security Engineer
Staff Application Security Engineer

United States Digital Space LLC • United States

Hybrid
USD 240,000 - 300,000
Up to four weeks of fully remote work per year
Application Security Manager
Application Security Manager

Alter Domus • Chicago (IL)

Hybrid
USD 120,000 - 150,000
Flexible arrangements
Generous holidays
Employee Share Plan