Назад
Company hidden
обновлено 2 дня назад

Application Security Engineer (Fintech)

20 200 - 29 100PLN
Формат работы
remote (только Europe/mena)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UAE, Poland, Spain, Romania, Portugal
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Application Security Engineer: Designing and building secure applications, performing security assessments, and leading penetration testing for a global financial super app. Focus on securing mobile apps, web applications, and APIs, validating bug bounty submissions, and integrating security into the SDLC.

Location: Remote from Poland, Portugal, Romania, Spain, or UAE; or Onsite in Dubai, Krakow, Lisbon, or Madrid

Salary: PLN20,200 - PLN29,100 gross monthly (Poland/Krakow)

Company

hirify.global is a financial super app helping 65+ million customers with spending, saving, investing, and more, fostering a diverse and inclusive culture.

What you will do

  • Perform security assessments on product designs, mobile apps (iOS/Android), web applications, and APIs.
  • Participate in Red Team missions and threat-led testing scenarios.
  • Lead and conduct penetration testing across applications, infrastructure, and APIs.
  • Manage and evolve the private bug bounty programme, validating submissions and ensuring timely resolution.
  • Contribute to and influence cloud security posture across GCP and AWS environments.
  • Partner with engineering teams to embed security into the software development lifecycle.

Requirements

  • 3+ years of hands-on experience in application security, penetration testing, or a related security engineering role.
  • Solid understanding of common web, mobile, and API vulnerabilities (e.g., OWASP Top 10, CWE).
  • Experience conducting code reviews, design reviews, and threat modeling for modern application architectures.
  • Familiarity with DevSecOps practices and integrating security tooling into CI/CD pipelines.
  • Working knowledge of authentication, authorization, session management, and cryptographic best practices.
  • Proficiency with security tools such as Burp Suite, MobSF, Frida, or custom scripts.

Nice to have

  • Experience participating in Red Team exercises.
  • Managing bug bounty programmes.
  • Contributing to open-source security tools or research.

Culture & Benefits

  • Certified as a Great Place to Work™.
  • Multicultural, hard-working team of 10,000+ people globally.
  • Commitment to an inclusive workplace and diverse talent.
  • Opportunity to build innovative products and services.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →

Текст вакансии взят без изменений

Источник - загрузка...