вчера

application security engineer in fintech

ориентир по рынку
вакансия зп не указана
в среднем 188 293 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовься к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме

описание

Altery builds products that help businesses and people move money across borders, currencies and digital assets with less friction.

задачи

  • Own security findings end to end: triage scanner and Bug Bounty results, validate them manually, assess exploitability, and build proofs of concept
  • Explain vulnerabilities to development teams and help them fix root causes
  • Build and improve the Secure SDLC by embedding security checks and gates into CI/CD pipelines
  • Review application architectures and new features through threat modelling and define clear security requirements
  • Dynamically test web, API, and mobile applications, focusing on business logic flaws scanners may miss
  • Strengthen software supply chain security and secrets management, including dependency control, secrets detection, and rotation
  • Report monthly on the application security posture and areas for improvement

требования

  • 2+ Years as an Application Security Engineer
  • Strong understanding of modern web and mobile architecture, including microservices, containers, CI/CD, and Secure SDLC principles
  • Hands-on experience integrating SAST, DAST, SCA, secret detection, container image scanning, and security gates into CI/CD pipelines
  • Experience triaging scanner and Bug Bounty findings, including manual validation, exploitability assessment, PoCs, and communicating fixes to developers
  • Solid web and API security testing skills beyond the OWASP Top 10, including CSP, security headers, cookies, and business logic flaws; confidence with common proxy and testing tools
  • Mobile application security testing experience based on OWASP MASVS/MASTG, including root and emulator detection, SSL pinning, and anti-tampering
  • Experience with threat modelling and security reviews of architecture decisions and new features
  • Practical knowledge of software supply chain security and secrets management
  • Fluent English for technical reading, writing, and communication
  • Takes ownership of findings through to resolution, collaborates with engineers, and is curious about learning, experimentation, AI, and automation
  • Будет плюсом: fintech or payments experience, including PSD2/SCA, cardholder data, PIN protection, and PCI DSS awareness; running or supporting a Bug Bounty programme or participating as a researcher; using AI and LLM tools in AppSec and understanding AI integration risks; cloud security basics, ideally AWS; ELK, security dashboards and metrics, and detecting sensitive data in logs; Security Champions programmes, secure coding checklists, or developer training; scripting for automation and data analysis; TCP/IP and core network and web protocols

условия

  • Competitive compensation that rewards your contribution
  • Flexible working hours aligned with local hours, with core hours from 9am–2pm UK time
  • Occasional visits to a nearby hub are welcomed
  • Wellbeing support, including additional sick leave
  • Career growth opportunities through ownership, skill development, and impact
  • Startup environment with a global team across countries, cultures, and time zones

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.