Назад
Company hidden
6 дней назад

Application Security Engineer (Fintech)

Формат работы
remote (Global)
Тип работы
fulltime
Грейд
middle
Английский
b2
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (Fintech): Securing web applications, APIs, and backend services across design, development, testing, and release workflows with an accent on vulnerability management, secure SDLC, and regulatory requirements. Focus on threat modeling, integrating security testing into CI/CD pipelines, coordinating cross-platform risks with mobile engineers, and remediating complex application security findings.

Location: Global; remote

Company

hirify.global is a Southeast Asian financial technology company building digital insurance and broader financial applications that help people plan, save, invest, spend, exchange, and travel.

What you will do

  • Secure web applications, APIs, and backend services across design, development, testing, and release workflows.
  • Perform security reviews, code reviews, penetration testing, and vulnerability assessments.
  • Identify, prioritize, track, and retest remediation for injection, broken access control, authentication, and configuration vulnerabilities.
  • Integrate SAST, DAST, software composition analysis, and secrets scanning into CI/CD pipelines.
  • Conduct threat modeling and design reviews for features, APIs, third-party integrations, and major changes.
  • Coordinate with mobile engineers on cross-platform risks and backend controls protecting native iOS and Android clients.

Requirements

  • Degree in Computer Science, Cybersecurity, or a related discipline, or equivalent experience.
  • At least 3 years of experience in application security, penetration testing, or secure software development.
  • Experience implementing and owning SC TRM and BNM RMiT application security and secure SDLC requirements.
  • Strong knowledge of OWASP Top 10, OWASP API Security Top 10, web vulnerabilities, API security, and secure design.
  • Hands-on experience with Burp Suite, OWASP ZAP, SAST, DAST, and dependency scanning tools.
  • Experience reviewing TypeScript/Node.js and Python services, with familiarity with Swift, Kotlin, AWS, and GCP. Strong English communication is required.

Culture & Benefits

  • Remote work from a global location.
  • Collaboration across global teams representing more than 20 nationalities.
  • English is the main working language.
  • Opportunity to build next-generation financial applications and improve developer security awareness.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →