Назад
Company hidden
10 часов назад

Senior Application Security Engineer (Fintech)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Serbia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Senior Application Security Engineer (Fintech): Improving the security of applications, APIs, and development processes with an accent on automating security testing and integrating it into CI/CD pipelines. Focus on building scalable security solutions, performing threat modeling, and developing AI-powered security workflows.

Location: On-site in Belgrade

Company

hirify.global is a global fintech company providing payment solutions.

What you will do

  • Drive secure software development practices and integrate security testing (SAST, DAST, SCA, API) into GitLab CI/CD pipelines.
  • Perform application security assessments, secure design reviews, and threat modeling for new and existing products.
  • Conduct manual source code reviews and support the remediation of complex security issues.
  • Own and improve Application Security Posture Management (ASPM) capabilities.
  • Develop AI-powered and agentic application security workflows for automated reviews and vulnerability triage.
  • Coordinate external penetration tests and translate emerging attack techniques into practical security improvements.

Requirements

  • Must be based in Belgrade for on-site work.
  • 5+ years of experience in Application Security, DevSecOps, or Software Engineering with a security focus.
  • Strong software development background and experience with modern application architectures.
  • Proficiency in scripting or programming (Java, Go, Python, Node.js, PHP, or Dart/Flutter).
  • Hands-on experience with SAST, DAST, SCA, and GitLab-based development workflows.
  • Strong understanding of Secure SDLC principles and practical application security engineering.

Nice to have

  • Offensive security background or practical penetration testing experience.
  • OSCP, OSWE, or similar offensive security certifications.
  • Experience with bug bounty programs or responsible vulnerability disclosure.
  • Knowledge of secure architecture design and security patterns.
  • Experience developing AI-powered security automation.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →