сегодня

application security engineer in fintech

ориентир по рынку
вакансия зп не указана
в среднем 343 365 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

We are looking for a technically strong Senior Application Security practitioner ready to take on real ownership. You will work directly with the Head of AppSec, contributing to the Secure Design practice and helping drive shift-left security across the organization.

задачи

  • Build and mature the Secure Design and Threat Modeling program by defining methodology, review standards, and sign-off criteria across the organization
  • Drive shift-left security initiatives by embedding security earlier in the development lifecycle through design reviews, developer enablement, and security gating in CI/CD
  • Own API security as a discipline
  • Support offensive security initiatives
  • Build and maintain security automation in Python to scale AppSec capacity
  • Work directly with developers on SAST and SCA remediation, scan optimization, and reducing friction in the security feedback loop
  • Contribute to AI-assisted security pipelines and define escalation paths, SLAs, and accountability structures for vulnerability management

требования

  • Hands-on experience across secure design, threat modeling, API security, and offensive security
  • Penetration testing experience and a solid understanding of real-world attack and API exploitation patterns
  • Deep familiarity with OWASP Top 10 in practice
  • Experience assessing REST and GraphQL APIs
  • Proficiency in Python and ability to build automation tools others can depend on
  • Experience in shift-left programs, including security in CI/CD, developer enablement, and design review processes
  • Understanding of web application and API security
  • Ability to read code across languages and engage with engineering teams at technical depth
  • Familiarity with cloud-native environments and attack surface management
  • Ability to influence across engineering and product and operate at architecture level
  • Будет плюсом: OSCP, OSWE, GWEB, CSSLP, CISSP, or CEH certifications, exposure to AI-assisted security tooling or LLM security, experience as a developer, fluency in Ruby, Python, and Scala

условия

  • Employees in this role work in the office four days and remotely one day (Friday)
  • Competitive salary, annual performance bonus, and equity for full-time employees
  • 100% Employer-paid health and dental insurance
  • Generous paid time off (PTO)

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.