Security Engineer
Core
Strengthen application security posture across digital products, platforms, and financial services systems by leading security assessments, driving remediation, and developing AppSec programs.
Role type
Senior IC application security engineer (AppSec)
Builds
AI-powered security automation tools, internal security tooling, integrations, and AI-assisted workflows
Domain
Financial services / Fintech / Application Security
Deliverable
production ML models | product features
Required skills
Application security assessments (SAST, DAST, manual code reviews, penetration testing), OWASP Top 10 and advanced vulnerability analysis, AI-driven security automation, Python/JavaScript coding, threat modeling, secure software development, cross-functional leadership
Preferred skills
OSCP/GWAPT/eWPT/CSSLP/CISSP certifications, banking/insurance/financial services domain knowledge, cloud security (AWS/Azure/GCP), mobile app security testing (iOS/Android), STRIDE/PASTA methodologies, red teaming/bug bounty experience
Technologies
Burp Suite Pro, OWASP ZAP, Metasploit, Python, JavaScript, AWS, Azure, GCP, iOS, Android
Responsibilities
Lead end-to-end application security assessments including SAST, DAST, manual code reviews, and penetration testing; Design, code, and deploy AI-powered automation tools and security scripts; Conduct threat modeling for complex, high-risk systems; Mentor and coach associate security engineers; Produce clear, risk-rated vulnerability reports with actionable remediation guidance
Seniority
Senior, hands-on IC with mentorship responsibilities
