Senior Application Security Engineer (Red Team)
Core
Conduct offensive security testing (pentesting) on web, API, mobile, and cloud infrastructure to identify vulnerabilities and improve security controls.
Role type
Senior Application Security Engineer (Red Team)
Builds
Secure AI platform for wealth management professionals
Domain
Fintech / Wealth Management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Web application pentesting, API security testing, Mobile application pentesting, Cloud security testing, Identity-focused offensive testing, Exploitability assessment, Offensive tooling development, Phishing and social-engineering assessment, Risk rating and remediation guidance
Preferred skills
Regulated environment experience (fintech), OWASP MASVS knowledge, Adversary emulation experience, OSCP/OSWE/GXPN certifications
Technologies
Burp Suite, Java, Spring, Terraform, Kubernetes
Responsibilities
Pentest web applications, APIs, infrastructure, Android, and iOS applications; Conduct cloud pentests and identity-focused offensive testing; Run purple-team exercises with Detection & Response; Develop offensive tooling and testing playbooks; Document findings with reproducible proofs-of-concept and actionable remediation guidance
Seniority
Senior, hands-on IC