Responsibilities
- Design and implement security controls for mobile applications, backend services, and web platforms
- Conduct threat modelling and risk assessments for new and existing systems
- Embed secure coding practices across engineering teams, aligned with OWASP standards
- Partner with engineers to ensure security is integrated throughout the software development lifecycle (SDLC)
- Identify and remediate application vulnerabilities and security risks
- Contribute to the implementation and improvement of DevSecOps practices
- Provide guidance on secure architecture and secure software design
- Support the development and enforcement of security policies, controls, and engineering standards
- Improve the organisation’s application security posture through proactive security reviews and testing
- Work with teams to ensure systems meet internal security standards and external regulatory requirements
- Provide security expertise for infrastructure components including containers and cloud-native environments
- Contribute to incident response and vulnerability management processes
Requirements
- 6+ years of experience in security engineering or application security
- 3+ years of experience in Application Security (AppSec)
- 3+ years of experience conducting threat modelling and risk assessments
- 3+ years of experience applying secure coding principles aligned with OWASP standards
- Strong understanding of application security vulnerabilities and mitigation strategies
- Proven experience collaborating with engineering teams to build secure-by-design applications
- 2–3 years of experience implementing DevSecOps practices
- 2–3 years of experience securing containerised environments such as Docker or Kubernetes
- 2+ years of experience applying cryptography and encryption techniques in application security
Nice to Have
- Experience working within a bank, fintech company, or other regulated environment
- Familiarity with financial services security standards and regulatory frameworks
- Experience securing mobile applications and modern web platforms
Work Arrangement
Remote (Worldwide)