Job
Core
Embed security throughout the software development lifecycle by partnering with engineering teams to identify, assess, and remediate vulnerabilities in applications and APIs.
Role type
Senior IC Application Security Engineer
Builds
Secure applications and APIs for a global fintech trading platform
Domain
Fintech / Application Security
Deliverable
production ML models | product features
Required skills
Application security assessments, threat modelling, secure code reviews, penetration testing, CI/CD pipeline integration, vulnerability triage, security standards definition, secure coding guidelines, bug bounty program management, third-party library evaluation, security training delivery
Preferred skills
Regulated financial services experience, Hungarian language skills
Technologies
Burp Suite, OWASP ZAP, Semgrep, Checkmarx, Snyk, Python, JavaScript, Java, Go, GitHub Actions, Jenkins, GitLab CI, AWS, Azure, GCP
Responsibilities
Perform application security assessments including threat modelling, secure code reviews, and penetration testing; Partner with development teams to integrate security controls into CI/CD pipelines; Identify, triage, and track vulnerabilities through to remediation; Define and maintain application security standards and secure coding guidelines; Champion security-by-design principles during new feature design; Lead and support bug bounty and responsible disclosure programmes; Conduct security training and awareness sessions for software engineers; Evaluate third-party libraries and vendor integrations for security risk
Seniority
Senior, hands-on IC