Назад
Company hidden
7 дней назад

Sr. Application Security Engineer (Fintech)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Sr. Application Security Engineer (AppSec/Fintech): Maturing the application security function by owning vulnerability remediation and building a secure development lifecycle with an accent on threat modeling and API security. Focus on preventing AI-assisted vulnerabilities, implementing SAST/DAST/SCA tooling, and establishing a Security Champions program.

Location: Remote (United States)

Company

hirify.global is a global leader in digital and biometric identity authentication, fraud prevention, and mobile deposit solutions.

What you will do

  • Own the application vulnerability remediation program and establish clear SLAs for developers.
  • Define and manage the SDLC, including security gates and review checkpoints in sprint and release processes.
  • Perform threat modeling for new features and architectural changes using STRIDE, PASTA, or equivalent.
  • Establish API security standards (OAuth 2.0, mTLS) and lead application penetration testing cycles.
  • Build and lead a Security Champions program and provide secure-coding training on OWASP Top 10.
  • Coordinate manual secure code reviews for security-sensitive components.

Requirements

  • 5–8 years of experience in application/product security or security-focused software engineering.
  • Experience with application penetration testing, including business-logic and API testing.
  • Hands-on experience with SAST, DAST, and SCA tuning and operationalization.
  • Ability to conduct secure code reviews across at least two web-application languages.
  • Expertise in threat modeling and deep knowledge of OWASP Top 10 and API security risks.
  • Must be based in the United States.

Nice to have

  • Experience in financial services, fintech, or SaaS for regulated industries.
  • Knowledge of financial-sector threats such as fraud, account takeover, and API abuse.
  • Experience with cloud-native application security, including container security.
  • Familiarity with PCI-DSS application security requirements.
  • Certifications such as OSCP, GWEB, or CSSLP.

Culture & Benefits

  • Comprehensive healthcare options (universal, supplemental, and private) based on location.
  • Retirement/pension plan contributions and participation in the MTK stock plan.
  • Generous annual leave, company holidays, and volunteer time off.
  • Support for continuous learning via e-learning licenses, tuition reimbursement, and hackathons.
  • Home office setup allowance.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →