Application Security Engineer
Brak informacji o wynagrodzeniu
MidFull-time
#416341·Dodano wczoraj·1
Źródło: nofluffjobs.comTech Stack / Keywords
SecurityAPIMicroservicessecurity architectureArchitecture
Firma i stanowisko
Papaya Global is a rapidly growing, award-winning B2B tech unicorn with over $400M raised from multiple tier-one investors. The company provides a comprehensive technology solution for managing global workforces, including payroll and payments in over 160 countries.
Wymagania
- 4+ years of hands-on experience in application security, product security, security architecture, or a closely related role.
- Strong understanding of secure software development lifecycles, threat modeling, security requirements, architecture reviews, and practical risk assessment.
- Hands-on experience with web applications, APIs, microservices, authentication, authorization, data protection, secrets management, and service-to-service communication.
- Practical code-reading or code-review experience in one or more modern programming languages, with the ability to explain security issues clearly to engineers.
- Background as a software developer or comparable hands-on experience such as DevOps engineering or software architecture involving daily code work.
- Experience with application-security tooling or equivalent capabilities such as vulnerability management, SAST, DAST, SCA, secret scanning, CSPM, or security testing platforms.
- Experience validating vulnerabilities and managing remediation from discovery through verified closure.
- Strong written and verbal communication skills, with the ability to influence R&D, DevOps, product, and business stakeholders without relying on authority alone.
- Experience using AI tools in day-to-day engineering work, including AI-assisted code review, vulnerability triage, and exploit development.
Obowiązki
- Own and mature the application-security and security-architecture programs across product and internal applications, APIs & services, and data stores.
- Conduct threat modeling, architecture reviews, security design reviews, and risk assessments for new systems and materially changed services.
- Define application-security requirements, review triggers, and practical security patterns for authentication, authorization, secrets, data protection, input handling, APIs, service-to-service communication, and security logging.
- Review source code, high-risk configurations, CI/CD security checks, and application integrations with engineering teams; provide actionable guidance to enhance security posture.
- Validate and prioritize findings from vulnerability-management and security-assessment tooling, penetration tests, and other security assessments. Translate findings into clear engineering tasks and track their status.
- Own the operating process for penetration testing and bug bounty programs, including scope, intake, triage, communication, remediation tracking, and verification of fixes.
- Identify recurring vulnerability themes and root causes; drive preventive improvements in engineering practices, tooling, architecture, and developer enablement.
- Partner with Security Operations to provide application context, logging requirements, detection opportunities, and context relevant to monitoring and incident response.
Papaya Global
6 aktywnych ofert