Remote job
Application Security Engineer AppSec
Job details
About this role
Role overview An application security engineer embedded with engineering teams to secure web applications, APIs, and backend services. The role brings security into design, development, testing, and release workflows while coordinating with mobile stakeholders on cross-platform risks. It also carries ownership of secure SDLC evidence for regulatory compliance frameworks.
Responsibilities - Perform security reviews, code reviews, and testing for web applications, APIs, and backend services - Identify, prioritize, and help remediate injection, broken access control, authentication, and configuration vulnerabilities - Integrate SAST, DAST, software composition analysis, and secrets scanning into CI/CD pipelines - Conduct threat modeling and design reviews for features, APIs, third-party integrations, and major changes - Coordinate with mobile engineers on cross-platform findings and on backend controls that protect native iOS and Android clients - Own application security implementation for SC TRM and BNM RMiT, including secure SDLC evidence, vulnerability management, testing, and audit remediation - Provide secure coding guidance, track remediation, retest fixes, and raise developer security awareness
Requirements - Degree in Computer Science, Cybersecurity, or a related discipline, or equivalent experience - 3+ years in application security, penetration testing, or secure software development - Experience implementing and owning SC TRM and BNM RMiT application security and secure SDLC requirements - Strong understanding of the OWASP Top 10, OWASP API Security Top 10, common web vulnerabilities, API security, and secure design principles - Hands-on experience with Burp Suite, OWASP ZAP, SAST, DAST, and dependency scanning tools - Experience reviewing TypeScript/Node.js and Python services, with familiarity in Swift, Kotlin, AWS, and GCP - Ability to work closely with developers, explain findings clearly, and support remediation end-to-end