TL;DR
Application Security Engineer: Designing and building secure applications, performing security assessments, and leading penetration testing for a global financial super app. Focus on securing mobile apps, web applications, and APIs, validating bug bounty submissions, and integrating security into the SDLC.
Location: Remote from Poland, Portugal, Romania, Spain, or UAE; or Onsite in Dubai, Krakow, Lisbon, or Madrid
Salary: PLN20,200 - PLN29,100 gross monthly (Poland/Krakow)
Company
hirify.global is a financial super app helping 65+ million customers with spending, saving, investing, and more, fostering a diverse and inclusive culture.
What you will do
- Perform security assessments on product designs, mobile apps (iOS/Android), web applications, and APIs.
- Participate in Red Team missions and threat-led testing scenarios.
- Lead and conduct penetration testing across applications, infrastructure, and APIs.
- Manage and evolve the private bug bounty programme, validating submissions and ensuring timely resolution.
- Contribute to and influence cloud security posture across GCP and AWS environments.
- Partner with engineering teams to embed security into the software development lifecycle.
Requirements
- 3+ years of hands-on experience in application security, penetration testing, or a related security engineering role.
- Solid understanding of common web, mobile, and API vulnerabilities (e.g., OWASP Top 10, CWE).
- Experience conducting code reviews, design reviews, and threat modeling for modern application architectures.
- Familiarity with DevSecOps practices and integrating security tooling into CI/CD pipelines.
- Working knowledge of authentication, authorization, session management, and cryptographic best practices.
- Proficiency with security tools such as Burp Suite, MobSF, Frida, or custom scripts.
Nice to have
- Experience participating in Red Team exercises.
- Managing bug bounty programmes.
- Contributing to open-source security tools or research.
Culture & Benefits
- Certified as a Great Place to Work™.
- Multicultural, hard-working team of 10,000+ people globally.
- Commitment to an inclusive workplace and diverse talent.
- Opportunity to build innovative products and services.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →