7 авг

application security engineer in fintech

ориентир по рынку
вакансия зп не указана
в среднем 343 365 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Unlimit is a global fintech ecosystem that provides payment processing, multi-currency business accounts, BaaS, and crypto gateways through a single platform. The company is transforming its infrastructure into AI-native financial infrastructure for businesses and AI agents.

задачи

  • Drive secure software development practices across the organisation;
  • Perform application security assessments, secure design reviews, and threat modelling for new and existing products;
  • Conduct manual source code reviews for business-critical applications and support remediation of complex security issues;
  • Integrate and optimise security testing throughout the SDLC, including SAST, DAST, Software Composition Analysis (SCA), API security testing, and Infrastructure as Code (IaC) security;
  • Build and improve automated application security workflows within GitLab CI/CD pipelines;
  • Own and continuously improve Application Security Posture Management (ASPM) capabilities;
  • Partner with software engineering teams to identify vulnerabilities early and implement practical, scalable security controls;
  • Support penetration testing activities by coordinating external assessments, validating findings, and driving remediation;
  • Contribute to internal AI-powered and agentic application security workflows, including automated security reviews, code analysis, and vulnerability triage;
  • Research emerging attack techniques and translate them into practical improvements across secure development and security testing;
  • Develop security guidance, reusable patterns, and engineering standards that enable developers to build secure software at scale.

требования

  • 5+ Years of experience in Application Security, Software Security, DevSecOps, or Software Engineering with a strong security focus;
  • Strong software development background with hands-on experience across modern application architectures;
  • Experience performing threat modelling, secure design reviews, and manual code reviews;
  • Strong understanding of Secure SDLC principles and practical application security engineering;
  • Experience implementing and maintaining automated security testing within CI/CD pipelines;
  • Hands-on experience with SAST, DAST, SCA, API security testing, ASPM, and modern application security tooling;
  • Practical understanding of modern attack techniques, exploitation methods, and secure coding practices;
  • Experience collaborating directly with engineering teams to remediate vulnerabilities and improve application resilience;
  • Strong scripting or programming skills in one or more of the following: Java, Go, Python, Node.js, PHP, or Dart (Flutter);
  • Experience working with GitLab-based development workflows;
  • A pragmatic, engineering-first mindset with a passion for automation and AI-assisted security;
  • Nice to have: Practical penetration testing experience or an offensive security background, bug bounty participation or responsible vulnerability disclosure experience, OSCP/OSWE or similar offensive security certifications, application or software architecture experience including secure architecture design and security patterns, AI-powered or agentic security automation experience, contributions to open-source security projects, security research, or technical community initiatives.

условия

  • Full-time employment.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.