Senior Application Security Engineer
New
D
DistribusionTravel Tech
We are a remote-first company with teams located around the Globe.Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years in AppSec (or 3+ years plus a strong software engineering/web-pentesting background)
- Required Skills
- PythonGCPKubernetesOAuthRubyTypeScriptGoCI/CD
Requirements
- 5+ years in AppSec (or 3+ years plus a strong software engineering/web-pentesting background).
- Track record of true ownership.
- Ability to read and write production code (Python, Go, TypeScript, Ruby, etc.).
- Deep understanding of web frameworks, CI/CD, and Kubernetes.
- Deep knowledge of web and API security, including OAuth2, JWT, rate limiting, tenant isolation, IDOR, and XSS.
- Strong cloud security fundamentals (GCP preferred) regarding public exposure, secrets hygiene, and WAF rules.
- Ability to prioritize by real-world risk and communicate complex risks to engineers and leadership.
Responsibilities
- Lead threat modeling and secure design reviews for high-risk changes, partner integrations, and payment flows.
- Implement, tune, and enforce security gates in GitLab CI/CD (SAST, SCA, secrets scanning, and DAST) while minimizing developer friction.
- Act as the primary technical owner for triaging, reproducing, and prioritizing findings from bug bounties, partner pentests, and automated scanners.
- Work hands-on with the DevOps team to implement GCP organizational policies, IAM least-privilege architectures, and Cloud Armor (WAF/rate limiting).
- Establish a security-champions network across engineering squads and leverage automation/AI-assisted tooling to scale code reviews effectively.
View Full Description & ApplyYou'll be redirected to the employer's site