Application Security Engineer/Lead
Core
Primary authority for ensuring security, resilience, and integrity of digital financial services, mobile platforms, and crypto systems.
Role type
Senior IC Application Security Lead
Builds
Secure software development lifecycle (SSDLC) practices, threat modeling capabilities, and security testing programs
Domain
Fintech, digital banking, e-commerce
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Secure coding practices, threat modeling (STRIDE), vulnerability management, SAST/DAST/SCA/IAST tool implementation, CI/CD pipeline security, mobile app vulnerability analysis (reverse engineering, certificate pinning), OWASP standards application, CREST penetration testing management, secure code training design
Preferred skills
CREST certifications, OSCP, OSWE, CSSLP
Technologies
Java, Python, Go, Node.js, AWS, GCP, Kubernetes, Docker, GitHub, GitLab, Bitbucket, Checkmarx, Semgrep, Snyk, Burp Suite Professional, SonarQube
Responsibilities
Define and implement enterprise Application Security strategy, standardize application security testing and vulnerability management, oversee SAST/DAST/SCA/IAST tools in CI/CD pipelines, lead architecture review and conduct threat modeling exercises, manage external penetration tests per CREST standards, design and deliver secure code training programs
Seniority
Senior, hands-on IC