Senior Application Security Engineer (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Application Security Engineer (Fintech): Strengthening system defenses through rigorous security reviews, penetration testing, and proactive threat modeling with an accent on application-layer protection and SDLC integration. Focus on managing Bug Bounty programs, tuning WAF controls, and empowering engineering teams through secure-by-design practices.
Location: Must be based in the United States (East Coast Time Zone), Canada, or Mexico.
Company
is a fast-growing fintech company building infrastructure for the crypto economy.
What you will do
- Conduct threat modeling reviews of Technical Design Documents (TDDs) for new and existing features.
- Perform application security assessments, including penetration testing and vulnerability research.
- Triage and respond to Bug Bounty program submissions, driving timely remediation.
- Manage and tune Cloudflare WAF and related application-layer security controls.
- Partner with engineering teams to embed security best practices throughout the SDLC.
- Develop security training and guidance to raise organizational security maturity.
Requirements
- Must be based in the US (East Coast Time Zone), Canada, or Mexico.
- Extensive experience across web/mobile application security and cloud infrastructure.
- Hands-on experience with white-box penetration testing and source code-assisted vulnerability discovery.
- Strong understanding of Threat Modelling principles and SDLC integration.
- Experience with WAFs and embedding security into CI/CD pipelines.
- Ability to read and review JavaScript and TypeScript codebases.
Nice to have
- Experience with Cloudflare hosting and WAF capabilities.
- Knowledge of GraphQL and REST API security testing.
- Interest or experience in Web3 security, including smart contracts and blockchain integrations.
- Security certifications such as OSCP or OSWE.
- Contributions to the security community (open source, CTFs, or speaking engagements).
Culture & Benefits
- Competitive salary and equity package with performance-based bonuses.
- Unlimited holidays and flexible working schedule.
- Private healthcare benefits and enhanced parental leave.
- Annual training budget and home office setup allowance.
- Monthly budget for products and zero-fee crypto transactions.
- Regular remote company offsites and hackathons.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →