Sr. Application Security Engineer (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Sr. Application Security Engineer (AppSec/Fintech): Maturing the application security function by owning vulnerability remediation and building a secure development lifecycle with an accent on threat modeling and API security. Focus on preventing AI-assisted vulnerabilities, implementing SAST/DAST/SCA tooling, and establishing a Security Champions program.
Location: Remote (United States)
Company
is a global leader in digital and biometric identity authentication, fraud prevention, and mobile deposit solutions.
What you will do
- Own the application vulnerability remediation program and establish clear SLAs for developers.
- Define and manage the SDLC, including security gates and review checkpoints in sprint and release processes.
- Perform threat modeling for new features and architectural changes using STRIDE, PASTA, or equivalent.
- Establish API security standards (OAuth 2.0, mTLS) and lead application penetration testing cycles.
- Build and lead a Security Champions program and provide secure-coding training on OWASP Top 10.
- Coordinate manual secure code reviews for security-sensitive components.
Requirements
- 5–8 years of experience in application/product security or security-focused software engineering.
- Experience with application penetration testing, including business-logic and API testing.
- Hands-on experience with SAST, DAST, and SCA tuning and operationalization.
- Ability to conduct secure code reviews across at least two web-application languages.
- Expertise in threat modeling and deep knowledge of OWASP Top 10 and API security risks.
- Must be based in the United States.
Nice to have
- Experience in financial services, fintech, or SaaS for regulated industries.
- Knowledge of financial-sector threats such as fraud, account takeover, and API abuse.
- Experience with cloud-native application security, including container security.
- Familiarity with PCI-DSS application security requirements.
- Certifications such as OSCP, GWEB, or CSSLP.
Culture & Benefits
- Comprehensive healthcare options (universal, supplemental, and private) based on location.
- Retirement/pension plan contributions and participation in the MTK stock plan.
- Generous annual leave, company holidays, and volunteer time off.
- Support for continuous learning via e-learning licenses, tuition reimbursement, and hackathons.
- Home office setup allowance.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →