We are looking for a Senior Application Security Engineer who builds secure development workflows, integrates security into CI/CD pipelines, and works hands-on with engineers to prevent critical vulnerabilities before code reaches production.
This role is for a builder who understands how applications fail, and uses that insight to engineer scalable, automated defenses across the SDLC.
Not SOC
Not compliance-only
Not a pentest role
Hands-on AppSec engineering
What You'll Do:
Threat Modeling
- Lead threat modeling and design reviews for critical banking features (Payments, Transfers, KYC).
- Identify business logic and architectural risks early — before implementation.
Secure SDLC & Pipeline Automation
- Design, integrate, and maintain SAST / DAST / SCA controls in CI/CD pipelines.
- Engineer guardrails that **block vulnerabilities automatically**, not just report them.
- Ensure security tools are tuned for signal, not noise.
Hands-On Code Security
- Perform manual code reviews on high-risk components (authentication flows, ledger logic, sensitive services).
- Work directly with developers to remediate issues with secure design patterns.
Secure Platform & Cloud Patterns
- Deliver secure-by-default templates (paved roads) for APIs, microservices, containers, cloud workloads, and AI-enabled services.
- Enable teams to deploy securely without slowing delivery.
Security Enablement & Culture
- Mentor engineers on secure coding practices.
- Support and grow a Security Champion culture across engineering teams.
What We're Looking For:
- Bachelors Degree in Computer Science or equivalent field.
- 5+ years of Application Security experience, with a background in software development.
- Strong understanding of secure coding principles and application failure modes.
- Proficiency in at least one backend language: Java (Spring Boot), Node.js, or Go
- Hands-on experience integrating security tools into CI/CD pipelines (e.g. GitHub Actions, Jenkins, GitLab CI).
- Solid knowledge of OWASP Top 10 and SANS Top 25 (applied in real systems, not just theory).
- Comfortable reviewing production code and discussing trade-offs with engineers.
Why This Role:
- Shape how secure software is built across a digital bank.
- Prevent vulnerabilities at scale, not one finding at a time.
- Work closely with strong engineering teams.
- High ownership, real impact on critical financial systems.
Good Fit If You Are:
- A security engineer who codes or reviews code regularly.
- Interested in **preventing vulnerabilities**, not just detecting them.
- Comfortable influencing developers through engineering, not enforcement.