Senior Application Security Engineer

New
D
DistribusionTravel Tech
We are a remote-first company with teams located around the Globe.Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
5+ years in AppSec (or 3+ years plus a strong software engineering/web-pentesting background)
Required Skills
PythonGCPKubernetesOAuthRubyTypeScriptGoCI/CD

Requirements

  • 5+ years in AppSec (or 3+ years plus a strong software engineering/web-pentesting background).
  • Track record of true ownership.
  • Ability to read and write production code (Python, Go, TypeScript, Ruby, etc.).
  • Deep understanding of web frameworks, CI/CD, and Kubernetes.
  • Deep knowledge of web and API security, including OAuth2, JWT, rate limiting, tenant isolation, IDOR, and XSS.
  • Strong cloud security fundamentals (GCP preferred) regarding public exposure, secrets hygiene, and WAF rules.
  • Ability to prioritize by real-world risk and communicate complex risks to engineers and leadership.

Responsibilities

  • Lead threat modeling and secure design reviews for high-risk changes, partner integrations, and payment flows.
  • Implement, tune, and enforce security gates in GitLab CI/CD (SAST, SCA, secrets scanning, and DAST) while minimizing developer friction.
  • Act as the primary technical owner for triaging, reproducing, and prioritizing findings from bug bounties, partner pentests, and automated scanners.
  • Work hands-on with the DevOps team to implement GCP organizational policies, IAM least-privilege architectures, and Cloud Armor (WAF/rate limiting).
  • Establish a security-champions network across engineering squads and leverage automation/AI-assisted tooling to scale code reviews effectively.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now