Job
Core
Build and scale the product security function for a fintech group, owning security practices from Secure SDLC to vulnerability management and developer enablement.
Role type
Senior Application Security Engineer (IC)
Builds
Secure fintech products (payment flows, back-office panels, partner integrations) for PSPs, EMIs, and neobanks
Domain
Fintech / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security, penetration testing, web security, API security, OWASP Top 10, business logic flaw analysis, source code analysis, CI/CD security tooling, risk prioritization
Preferred skills
OSCP/OSWE/BSCP certification, bug bounty program management, AI-assisted vulnerability triage, Kubernetes security, AWS security, mobile security testing, PCI DSS experience
Technologies
Semgrep, Trivy, gitleaks, Checkov, GitLab CI, Go, PHP, JavaScript
Responsibilities
Roll out Secure SDLC process, run security design reviews, own SAST/SCA/secret scanning in CI/CD, triage vulnerability findings, perform hands-on security testing of web apps and APIs, launch and manage bug bounty program, train developers on secure coding, provide evidence for PCI DSS and DORA audits
Seniority
Senior, hands-on IC
