App Sec Engineer (Application Security)
Core
Application Security Engineer embedded in the development lifecycle to own AppSec across the engineering function, running threat models, reviewing code, and ensuring secure tooling for a scaling SaaS platform handling sensitive financial data.
Role type
Application Security Engineer
Builds
Secure SaaS platform handling sensitive financial data
Domain
Fintech, Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security in SaaS/Fintech, SAST/DAST/SCA tooling (Snyk, Checkmarx, Semgrep, Burp Suite), Threat modelling, OWASP Top 10 remediation, API security (REST, GraphQL), Secure SDLC/CI/CD integration, Auth concepts (OAuth, OIDC, JWT, SAML), Risk communication
Technologies
Snyk, Checkmarx, Semgrep, Burp Suite
Responsibilities
Run threat models with engineering and product teams, Review code for vulnerabilities, Embed security into CI/CD pipelines, Educate developers on secure practices, Communicate security risks to stakeholders
Seniority
Mid-Senior, hands-on IC
