Posted on: 18/09/2026
Application Security (AppSec) Engineer (Fintech & Logistics)
About Us & Our Mission :
Protecting sensitive financial ledgers, transactional user data, and enterprise supply chain telemetry requires proactive threat modeling, continuous vulnerability scanning, and uncompromised security guardrails. At our company, security is never treated as an afterthought or a compliance checkbox; it is baked directly into our engineering DNA. If you want to safeguard complex, high-throughput systems against modern cyber threats and secure infrastructure at scale, you will find your calling here.
The Role & Impact :
We are seeking a meticulous and proactive Application Security (AppSec) Engineer to take charge of our security posture across our fintech and logistics platforms. You will work hand-in-hand with our software engineering, DevOps, and product squads to embed security best practices throughout the entire software development lifecycle (SDLC). Your work will directly protect millions of user transactions and ensure absolute trust in our digital infrastructure.
Key Responsibilities :
- Code Reviews & Threat Modeling : Conduct regular architectural threat modeling sessions, security code reviews, and automated SAST/DAST scans.
- Pipeline Security Guardrails : Implement and maintain automated security checks, dependency vulnerability scanning, and secret management within GitHub Actions CI/CD pipelines.
- Penetration Testing : Lead regular internal and external penetration testing exercises across web applications, mobile apps, REST APIs, and cloud microservices.
- Incident Response & Triage : Act as the primary technical responder for security alerts, investigating potential breaches, conducting root-cause analysis, and hardening systems.
- Compliance Management : Oversee and maintain rigorous security compliance frameworks and audits, including SOC 2 Type II and ISO 27001 standards.
What We Are Looking For :
- Experience : 2 - 5 years of professional information security, AppSec, or penetration testing experience within tech product or SaaS companies.
- Technical Knowledge : Strong understanding of OWASP Top 10 vulnerabilities, secure coding principles in Python/Node.js/TypeScript, and cloud security architecture (AWS/GCP IAM policies).
- Tooling Proficiency : Hands-on experience with vulnerability scanners, static/dynamic code analysis tools (SonarQube, Snyk, Burp Suite), and container security tools.
- Communication Skills : Excellent ability to explain complex security risks and remediation steps clearly to non-security engineering teams.
- Certifications (Preferred) : Relevant security certifications such as CEH, OSCP, CISSP, or AWS Certified Security are a strong plus.
What We Offer :
- Competitive Package : Industry-standard salary bracket (16 - 28 LPA) backed by performance bonuses and equity options.
- High-Impact Role : Total autonomy to shape company-wide security standards and tooling infrastructure.
The job is for:
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1672465