Application Security Engineer
Core
Embed security throughout the software development lifecycle by partnering with engineering teams to identify, assess, and remediate vulnerabilities in applications and APIs.
Role type
Application Security Engineer
Builds
Secure applications and APIs for a global fintech trading platform
Domain
Fintech / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security assessments, threat modelling, secure code reviews, penetration testing, CI/CD pipeline integration, vulnerability triage, security standards definition, bug bounty program management, third-party library evaluation
Preferred skills
Financial services domain experience, Hungarian language skills
Technologies
Burp Suite, OWASP ZAP, Semgrep, Checkmarx, Snyk, Python, JavaScript, Java, Go, GitHub Actions, Jenkins, GitLab CI, AWS, Azure, GCP
Responsibilities
Perform application security assessments including threat modelling, secure code reviews, and penetration testing; Partner with development teams to integrate security controls into CI/CD pipelines; Identify, triage, and track vulnerabilities through to remediation; Define and maintain application security standards and secure coding guidelines; Champion security-by-design principles during architecture phases; Lead and support bug bounty and responsible disclosure programmes; Conduct security training and awareness sessions for software engineers; Evaluate third-party libraries and vendor integrations for security risk
Seniority
Senior, hands-on IC