We are hiring an experienced Application Security (AppSec) Engineer to strengthen secure software development across our products and platforms. You will collaborate with development teams, perform secure code reviews, lead threat modeling sessions, orchestrate security testing, and ensure our applications meet the highest security and compliance standards. If you enjoy diving deep into code, uncovering vulnerabilities, and shaping secure architecture, this role is a perfect fit.
Responsibilities
- Define and enforce secure coding standards
- Review application design and architecture for security flaws
- Conduct threat modeling for new features and systems
- Manual secure code review
- Maintain and tune SAST / SCA tools
- Validate vulnerabilities, eliminate false positives, and drive remediation
- Conduct DAST, API testing, fuzzing, and business logic testing
- Support penetration testing and coordinate remediation efforts
- Analyze exploit paths and help development teams fix issues securely
- Ensure compliance with NCA, ISO 27034, OWASP SAMM / ASVS
- Maintain AppSec policies, checklists, and risk registers
- Deliver security awareness training for engineering teams
- Work closely with DevOps teams to embed AppSec into CI / CD
- Implement security gates and enforcement checks
- Contribute to architecture reviews and technical decisions
Qualification
4–10+ years in Application Security or Secure DevelopmentHands-on experience with SAST / DAST / SCA toolsStrong experience performing manual secure code reviewStrong grasp of OWASP Top 10, ASVS, API Top 10, CWE Top 25Familiarity with API security, JWT, OAuth2, OIDCExperience with cloud and container security fundamentalsAbility to guide developers on secure coding practicesNice to Have
OSWE (highly preferred)OSCP / OSEP / GWAPTCSSLPExperience in microservices, distributed systems, or cloud-native securityExperience with threat modeling frameworks (STRIDE, PASTA)Why Join Us?
Exposure to large-scale engineering & security challengesStrong learning culture & mentorship