Senior Application Security Engineer (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Application Security Engineer (Fintech): Owning application security across a mobile banking platform, payments stack, and regulated products with an accent on threat modeling, secure SDLC, mobile testing, and supply chain security. Focus on making risk-based release decisions, strengthening CI/CD controls, and translating application security gaps for engineers, the CISO, and regulatory stakeholders.
Location: Remote; available locations include Georgia, Bangkok, the European Union, Kazakhstan, Kuala Lumpur, Poland, and Serbia.
Company
develops mobile banking, payments, and regulated financial products.
What you will do
- Own application security across mobile banking, payments, and regulated products, reporting to the Group CISO.
- Assess product and data-flow risk, maintain the application security risk register, and manage risk acceptance and remediation decisions.
- Build and improve the secure SDLC, including threat modeling before design completion and a mobile security testing baseline.
- Improve CI/CD security signal and own supply chain controls such as dependency pinning, SBOMs, internal registries, and compromised-package response.
- Manage secrets detection and remediation end to end.
- Coordinate security input for product launches and communicate security gaps to engineering, leadership, and BSP examiners.
Requirements
- 7+ years of application security experience with ownership of technical work and security processes.
- Experience building or substantially improving a secure SDLC in a fast-moving product organization.
- Hands-on threat modeling, vulnerability management, remediation tracking, SLA management, and risk acceptance experience.
- Production mobile security testing experience with iOS and/or Android.
- Knowledge of SAST, DAST, SCA, API security, OWASP ASVS/MASVS, SBOMs, dependency risk management, and secrets management.
- Ability to write Python or Bash automation; working knowledge of AWS and containers.
Nice to have
- Experience in financial services or another regulated environment.
- Familiarity with PCI-DSS, ISO 27001, or BSP MORB.
- OSCP, GWEB, GWAPT, or CSSLP certification.
Culture & Benefits
- Remote full-time work across the listed locations.
- Async-first day-to-day communication with strong written English.
- Close collaboration with engineering teams and the Bank IS function.
- Risk-driven security ownership focused on practical controls rather than compliance checklists.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →