Назад
Company hidden
21 час назад

Application Security Engineer\Lead (Fintech)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Indonesia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer\Lead (Fintech): Leading application security for digital financial services, mobile platforms, and crypto systems with an accent on SSDLC, OWASP standards, threat modeling, and CREST-aligned penetration testing. Focus on integrating SAST/DAST/SCA/IAST into CI/CD workflows, managing vulnerability remediation, and enabling engineering teams through secure coding training.

Location: Jakarta, Indonesia; hybrid workplace

Company

hirify.global develops digital financial services supporting financial inclusion in Indonesia, including mobile and crypto platforms.

What you will do

  • Define and implement the enterprise Application Security strategy across engineering teams.
  • Standardize security testing, code reviews, and vulnerability management using OWASP Top 10, ASVS, and SAMM.
  • Manage SAST, DAST, SCA, and IAST tooling in CI/CD pipelines and guide remediation.
  • Lead architecture reviews and STRIDE-based threat modeling during early product design.
  • Manage external penetration testing, including scope, execution, vendor alignment, and remediation tracking.
  • Build secure coding training programs and a Security Champions network.

Requirements

  • 8+ years of information security experience, including 3+ years leading application or product security in fintech, digital banking, or e-commerce.
  • Strong software development background with Java, Python, Go, or Node, plus cloud-native experience with AWS or GCP, Kubernetes, and Docker.
  • Expertise in mobile application vulnerabilities, reverse engineering, certificate pinning, and secure storage.
  • Hands-on experience with GitHub, GitLab, Bitbucket, Checkmarx, Semgrep, Snyk, Burp Suite Professional, and SonarQube.
  • Proven application of OWASP standards to web, mobile, and API layers, with experience managing or executing CREST-accredited assessments.
  • Strong communication skills for translating software vulnerabilities into business risks and actionable engineering fixes.

Nice to have

  • CREST certifications or equivalent expert-level certifications such as OSCP, OSWE, or CSSLP.

Culture & Benefits

  • Hybrid work arrangement in Jakarta, Indonesia.
  • Opportunity to contribute to increased financial inclusion in Indonesia.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →