Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
описание
Altery builds products that help businesses and people move money across borders, currencies and digital assets with less friction.
задачи
Own security findings end to end: triage scanner and Bug Bounty results, validate them manually, assess exploitability, and build proofs of concept
Explain vulnerabilities to development teams and help them fix root causes
Build and improve the Secure SDLC by embedding security checks and gates into CI/CD pipelines
Review application architectures and new features through threat modelling and define clear security requirements
Dynamically test web, API, and mobile applications, focusing on business logic flaws scanners may miss
Strengthen software supply chain security and secrets management, including dependency control, secrets detection, and rotation
Report monthly on the application security posture and areas for improvement
требования
2+ Years as an Application Security Engineer
Strong understanding of modern web and mobile architecture, including microservices, containers, CI/CD, and Secure SDLC principles
Hands-on experience integrating SAST, DAST, SCA, secret detection, container image scanning, and security gates into CI/CD pipelines
Experience triaging scanner and Bug Bounty findings, including manual validation, exploitability assessment, PoCs, and communicating fixes to developers
Solid web and API security testing skills beyond the OWASP Top 10, including CSP, security headers, cookies, and business logic flaws; confidence with common proxy and testing tools
Mobile application security testing experience based on OWASP MASVS/MASTG, including root and emulator detection, SSL pinning, and anti-tampering
Experience with threat modelling and security reviews of architecture decisions and new features
Practical knowledge of software supply chain security and secrets management
Fluent English for technical reading, writing, and communication
Takes ownership of findings through to resolution, collaborates with engineers, and is curious about learning, experimentation, AI, and automation
Будет плюсом: fintech or payments experience, including PSD2/SCA, cardholder data, PIN protection, and PCI DSS awareness; running or supporting a Bug Bounty programme or participating as a researcher; using AI and LLM tools in AppSec and understanding AI integration risks; cloud security basics, ideally AWS; ELK, security dashboards and metrics, and detecting sensitive data in logs; Security Champions programmes, secure coding checklists, or developer training; scripting for automation and data analysis; TCP/IP and core network and web protocols
условия
Competitive compensation that rewards your contribution
Flexible working hours aligned with local hours, with core hours from 9am–2pm UK time
Occasional visits to a nearby hub are welcomed
Wellbeing support, including additional sick leave
Career growth opportunities through ownership, skill development, and impact
Startup environment with a global team across countries, cultures, and time zones