Application Security Engineer
Core
Strengthen security across Sunbit's products, services, and development lifecycle by identifying gaps, designing controls, and implementing secure patterns for applications, APIs, and AI features.
Role type
Senior IC application security engineer (DevSecOps)
Builds
Scalable security controls, reusable security libraries, developer tooling, and AI-powered security capabilities
Domain
Financial technology, cloud-native security, AI security
Deliverable
production ML models | product features
Required skills
Application security, DevSecOps, API security, threat modeling, secure code review, CI/CD security, authentication and authorization, cryptography, cloud security (AWS, Kubernetes), software engineering
Preferred skills
AI agent development, LLM security, ASPM/WAF, policy as code, offensive security, regulated fintech experience
Technologies
GitHub Actions, SAST, DAST, SCA, Terraform, AWS, Kubernetes, OIDC, SAML
Responsibilities
Identify security gaps and translate them into technical solutions; Design and implement scalable security controls; Review architectures and run threat modeling; Secure APIs, auth flows, and data handling; Own secure SDLC including pipeline gates; Build reusable security tooling and AI agents; Partner with R&D and DevOps teams
Seniority
Senior, hands-on IC (via careerplan.io/jobs/37-001-32-A60-application-security-engineer-at-sunbit)
