Papaya Global
Papaya Global
New

Application Security Engineer

Brak informacji o wynagrodzeniu
MidFull-time
#416341·Dodano wczoraj·1
Źródło: nofluffjobs.com
Aplikuj szybko

Tech Stack / Keywords

SecurityAPIMicroservicessecurity architectureArchitecture

Firma i stanowisko

Papaya Global is a rapidly growing, award-winning B2B tech unicorn with over $400M raised from multiple tier-one investors. The company provides a comprehensive technology solution for managing global workforces, including payroll and payments in over 160 countries.

Wymagania

  • 4+ years of hands-on experience in application security, product security, security architecture, or a closely related role.
  • Strong understanding of secure software development lifecycles, threat modeling, security requirements, architecture reviews, and practical risk assessment.
  • Hands-on experience with web applications, APIs, microservices, authentication, authorization, data protection, secrets management, and service-to-service communication.
  • Practical code-reading or code-review experience in one or more modern programming languages, with the ability to explain security issues clearly to engineers.
  • Background as a software developer or comparable hands-on experience such as DevOps engineering or software architecture involving daily code work.
  • Experience with application-security tooling or equivalent capabilities such as vulnerability management, SAST, DAST, SCA, secret scanning, CSPM, or security testing platforms.
  • Experience validating vulnerabilities and managing remediation from discovery through verified closure.
  • Strong written and verbal communication skills, with the ability to influence R&D, DevOps, product, and business stakeholders without relying on authority alone.
  • Experience using AI tools in day-to-day engineering work, including AI-assisted code review, vulnerability triage, and exploit development.

Obowiązki

  • Own and mature the application-security and security-architecture programs across product and internal applications, APIs & services, and data stores.
  • Conduct threat modeling, architecture reviews, security design reviews, and risk assessments for new systems and materially changed services.
  • Define application-security requirements, review triggers, and practical security patterns for authentication, authorization, secrets, data protection, input handling, APIs, service-to-service communication, and security logging.
  • Review source code, high-risk configurations, CI/CD security checks, and application integrations with engineering teams; provide actionable guidance to enhance security posture.
  • Validate and prioritize findings from vulnerability-management and security-assessment tooling, penetration tests, and other security assessments. Translate findings into clear engineering tasks and track their status.
  • Own the operating process for penetration testing and bug bounty programs, including scope, intake, triage, communication, remediation tracking, and verification of fixes.
  • Identify recurring vulnerability themes and root causes; drive preventive improvements in engineering practices, tooling, architecture, and developer enablement.
  • Partner with Security Operations to provide application context, logging requirements, detection opportunities, and context relevant to monitoring and incident response.
Papaya Global

Papaya Global

6 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj szybko